Forum Discussion

Skipster311-1's avatar
Skipster311-1
Iron Contributor
Aug 17, 2021
Solved

Outlook report add-in

Hello

In an effort to move away from users using "safe senders" in outlook we are considering using the report add-in. However when i review the permissions the add-in has its a bit concerning. Im reluctant to push out this add-in because the add-in has permissions to read and change email in a users mailbox. Seems excessive 

 

 

  • Skipster311-1 

     

    Hi,

     

    Users or admins can add senders to the Safe Senders list of the mailbox, but this is not desirable in most situations since senders will bypass parts of the filtering stack. Although you trust the sender, the sender can still be compromised and send malicious content. It is best that you let our filters do what is needed to check every message and then report the false positive/negative to Microsoft if our filters got it wrong. Bypassing the filtering stack also interferes with ZAP.

     

    As far as the Report Message add-in is concerned, the permissions are necessary. As stated in other comments, we do need to read the contents, but that is based on and only for what the end-user wants to report. The change permission is similar in that we move the message between folders when users report something. For example, if you report a phish, we will move the item from the Inbox to the Deleted Items folder if necessary.

     

    I hope this addresses your concerns. By the way, admin submissions is also another way to submit messages to Microsoft for review without installing the add-in but it does require the admin to find instead. More details can be found here: Manage submissions - Office 365 | Microsoft Docs.

     

    Thanks!

     

     

  • Skipster311-1 

     

    Hi,

     

    Users or admins can add senders to the Safe Senders list of the mailbox, but this is not desirable in most situations since senders will bypass parts of the filtering stack. Although you trust the sender, the sender can still be compromised and send malicious content. It is best that you let our filters do what is needed to check every message and then report the false positive/negative to Microsoft if our filters got it wrong. Bypassing the filtering stack also interferes with ZAP.

     

    As far as the Report Message add-in is concerned, the permissions are necessary. As stated in other comments, we do need to read the contents, but that is based on and only for what the end-user wants to report. The change permission is similar in that we move the message between folders when users report something. For example, if you report a phish, we will move the item from the Inbox to the Deleted Items folder if necessary.

     

    I hope this addresses your concerns. By the way, admin submissions is also another way to submit messages to Microsoft for review without installing the add-in but it does require the admin to find instead. More details can be found here: Manage submissions - Office 365 | Microsoft Docs.

     

    Thanks!

     

     

  • ExMSW4319's avatar
    ExMSW4319
    Steel Contributor
    That should only be a concern if your Outlook clients are driven by on-premises Exchange intentionally to keep any other party out of your mailboxes. For the average Exchange Online customer, the add-in does not confer any access that Microsoft do not already have. If you have an on-premises Exchange server screened by a third-party system, you might want to consider the third party's Outlook add-in instead or ask why they have not developed one.

    Weight against that the fact that unless you have some very good detection rules running, the add-in is important in shortening your organisation's feedback time to Defender for O365. Prompt reactions by your recipients will improve your ZAP response times.
    • Skipster311-1's avatar
      Skipster311-1
      Iron Contributor
      Understood. Is this feature Microsoft's approach to replacing "safe senders" in outlook? I notice Microsoft doesn't recommend using "safe senders"

Resources