Forum Discussion

JoostvdLinden's avatar
JoostvdLinden
Copper Contributor
Sep 18, 2023

SharePoint file request email blocked as high confidence phish in Exchange Online

Hi all,

 

I am trying to put the file request feature to use in an automated business process, more info: Create a file request - Microsoft Support

It is my idea to send out this file request link to an external recipient fully automated.

 

However, when I send out the file request through SharePoint or by manually adding the URL to an email, the email gets quarantined.

I have raised a support request with Microsoft. The outcome is: "the message was marked as HighConfidencePhish with the action Quarantine as a result of the policy HostedContentFilterPolicy/261b70a3-b2ce-4782-a536-145ffe358139 being applied to the message. The message was flagged as Phish due to Machine Learning Model M360."

 

The feedback was to submit the email file to Submissions in the Defender portal, and that's all they can do...

At first I'm wondering how it is possible that a standard feature of SharePoint Online gets blocked by other Microsoft 365 tenants. Second, is this submission really taken serious or will it require more end users to report the same issue before we experience this behavior. The latter would probably prevent me from further using this feature for this business process.

 

Thanks for all help provided!

BR, Joost

1 Reply

  • Dan_Snape's avatar
    Dan_Snape
    Steel Contributor
    Submissions are definitely acted on. Normally a temporary allow will be configured on the submitted message while they investigate the false positive. Malicious actors have used SharePoint Online in the past. If you can get details of what part of the message triggered the detection as phishing, maybe you can alter how it's sent to avoid this.

Resources