Event banner
Microsoft Defender for Office 365 Ask Microsoft Anything
Event Ended
Wednesday, May 31, 2023, 09:00 AM PDTEvent details
This March we announced the public preview of collaboration security for Microsoft Teams. We are bringing the full feature set that customers use to protect their email environments across prevention...
Trevor_Rusher
Updated May 31, 2023
CRL55
May 31, 2023Copper Contributor
Can we 'allow list' internal senders who are getting blocked from sending outbound due to the following. ?
(Basically a false positive)
"Alert description
User has been detected as sending suspicious messages outside the organization and will be restricted if this activity continues. -V1.0.0.1"
- johnengelsMay 31, 2023
Microsoft
CRL55 - A bit of further clarification on Dhairyya's comment. You cannot remove this protection/control, as it is designed to prevent compromised users from affecting the organization/domain from compromise and abuse (i.e. email domain reputation protection). It is flagging cases where the user is sending out messages that are being detected as suspicious (spam) or malicious (phish/malware) within the broader Exchange Online environment. If left unchecked, it could mean that other emails from your organization get blocked or junked - in some cases by other third party cloud email services might be doing the same. This alert/protection most often triggers for people sending out legitimate emails when sending out advertising, newsletters, etc. that contain links. Office isn't intended for marketing email purposes, so the limits are set relatively low and may get triggered when sending to big volumes of users or distribution lists that have many names. You can adjust the users' limits up or down, but I'm not aware of how high you can set it. Bumping it up too much could affect domain reputation and should not be done en masse - instead limit it to specific users/groups. The specific policy to use is the outbound spam policy and target specific users try some higher message limits - Dhairyya_AgarwalMay 31, 2023
Microsoft
Thanks for your question, CRL55. That is not possible as it when you get this alert it might be sign of an account compromise as the user might be sending malicious messages out. So, you need to actually need to check or tweak your outbound policy.- CRL55May 31, 2023Copper ContributorThanks - but weve been around the houses and investigated to the nth degree and the email/sender/ip/contents/attachment are also completely legitimate. Having to go into 'restricted entities' every other day to clear unblock them is a bit of a pain. Thanks Anyway
Location
Microsoft Tech Community