Forum Discussion
MaxSmile8
Jan 18, 2022Copper Contributor
Any way to add comments or notes to an item in Quarantine?
Hi, We have multiple Quarantine admins in our organization. The admins work across different time zones and act on the Quarantined emails. Currently we don't know if an email was already ...
FaithEbenezerOquong
Microsoft
Feb 15, 2022we audit every action that is taken by an Admin on the quarantine console in their audit logs. does this help?
MaxSmile8
Feb 16, 2022Copper Contributor
Thanks for the tip. How and where should we conduct the audit?
- FaithEbenezerOquongFeb 16, 2022
Microsoft
please see here: https://answers.microsoft.com/en-us/msoffice/forum/all/how-to-track-whom-of-admins-released-email-from/3331618f-9a97-460b-935a-de839b1f2566- MaxSmile8Feb 17, 2022Copper ContributorThank you very much.
This audit tool will help us find the released messages from Quarantine. (satisfies one part of our requirement). The only challenge I see here is matching the "Item ID" from the audit result to the actual email released.
Challenge #2
Our business blocks repeated spammers even from the Quarantine, we do this using mail flow rules (block emails, domains, keywords etc) and connection filter to block IPs.
Is there a way to also audit connection filter and mail flow rules?- ExMSW4319Feb 27, 2022Iron Contributor
If you are engaging hostile mail with mail flow rules, you can have actions to add a subject line tag or a header to intercepted messages before you send them to the hosted quarantine.
I audit most of my mail flow rules with a week-end PowerShell script doing get-maildetailtransportrulereport -transportrule $rule on the more interesting ones. If you have a rule with a very high engagement rate, you may run into throttling problems.
To answer the original posting, would it not be worth saying that if an analyst takes the time to examine a message in the hosted quarantine, that message should then be deleted? If the prior action was to release or download, that might also appear in the audit?