Forum Discussion
Robert Bollinger
Jul 01, 2022Brass Contributor
Malware Infected Messages, URL
Hey Team, Hoping you can assist here. We have an issue where messages which are "Known Threats" due to the URL, are classified as Phish instead of Malware, and are then placed into quarantine, ...
Robert Bollinger
Jul 05, 2022Brass Contributor
We ended up opening a support ticket with Microsoft for this. As usual it wasn't a good experience. Microsoft was not able to tell us what happened with that message. nor why it was placed in the "SPAM" vs "High Confidence SPAM" quarantine.
However as an alternative, we were able to create a new Quarantine policy we set the policy to "Request Release" + "Notification" enabled.
Then set the newly created policy for the High Confidence SPAM, Phishing and Bulk Queues. We were also able to determine (from the ticket) the correct agent that acted on the message, and that's how we knew which policy group to work with (Anti Spam, Anti Phishing).
However as an alternative, we were able to create a new Quarantine policy we set the policy to "Request Release" + "Notification" enabled.
Then set the newly created policy for the High Confidence SPAM, Phishing and Bulk Queues. We were also able to determine (from the ticket) the correct agent that acted on the message, and that's how we knew which policy group to work with (Anti Spam, Anti Phishing).