Forum Discussion

SeniorBraddah's avatar
SeniorBraddah
Copper Contributor
Apr 21, 2022

Safe Links policies for email messages

I've been monitoring our secure score pretty hard lately and noticed "9 points regressed for Create Safe Links policies for email messages".   I went to our Safe Links policy and sure enough, the two recommended items were already configured.  I restarted the policy, and i'm waiting for the "real-time" secure score to update, but it is not. 

 

How do you guys go about resolving issues like this?

  • Marius_S's avatar
    Marius_S
    Copper Contributor
    And finally on May 1st I've got my points back. Seems Microsoft has fixed the detection. I hope also for you all.
    • Maxim_vanL's avatar
      Maxim_vanL
      Copper Contributor
      Confirmed that detection has been fixed for my tenant at least.
  • AndrewEI's avatar
    AndrewEI
    Copper Contributor

    SeniorBraddah 

    Can confirm, this is happening to me too.
    I have two fresh tenancies i'm building for clients.

    Implementation status
    100% of users are affected by policies that are configured less securely than is recommended

     

     

  • Maxim_vanL's avatar
    Maxim_vanL
    Copper Contributor

    SeniorBraddah The test I started yesterday (see my other comment) has been completed. I created a new policy with the correct settings and assigned it to a single user. Secure Score now mentions both policies with the correct number of users and states that both policies are configured less securely than recommended.

     

    So it seems the detection is incorrect.

     

  • Cristian_N's avatar
    Cristian_N
    Copper Contributor
    Same issue here. Regressed almost 8 points for Safe Links on Apr. 20th.
  • Maxim_vanL's avatar
    Maxim_vanL
    Copper Contributor
    Same here. Today I created a new policy with the same settings and applied it to one user (Also excluded that user from the original policy). Hopefully that will be scored in which case I will assign all users to the new policy and delete the old one. If it doesn't work, I will at least see if the implementation status is updated (both policies should appear). If the status is updated but the scoring is not, I will change the status manually to "Resolved through alternate mitigation". Once every 3 months, I analyze all the items with status other then "Completed" to see if detection has improved or previously accepted risks are still acceptable.
  • baluntz's avatar
    baluntz
    Copper Contributor
    Same exact issue here. Regressed 9 points for Safe Links on Apr. 20. No change was made to the policy at the time. Tried disabling and re-enabling the policy. Also verified that safe links is still re-writing our URLs. Points have not come back since.
  • Marius_S's avatar
    Marius_S
    Copper Contributor

    Same issue here. Regressed 9 points for the Safe Links suddenly on Apr. 20.
    Double checked the policy (which of course was not even changed) and all seems according to recommendation.

  • snickadmin's avatar
    snickadmin
    Copper Contributor

    SeniorBraddah 

     

    Same thing here. I'm trying to improve score and created the necessary policies which made me gain some points. Suddenly, one day, I regressed 9 points, next day gained 9 points again, only to lose them again the following day.  No changes were made to the organisation or policies. 

     

    Safe Links Policy states that 100% of my users are affected by this policy. So they are all covered.

     

    Anyone have a clue? 

Resources