Home

Cannot block emails with specific label using MailFlow rules (OWA only)

%3CLINGO-SUB%20id%3D%22lingo-sub-1012402%22%20slang%3D%22en-US%22%3ECannot%20block%20emails%20with%20specific%20label%20using%20MailFlow%20rules%20(OWA%20only)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1012402%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20configured%20a%20mailflow%20rules%20in%20Exchange%20Online%20that%20will%20block%20any%20email%20that%20is%20labeled%20with%20a%20specific%20sensitivity%20label%20and%20that%20is%20sent%20outside%20the%20organization%20from%20being%20delivered.%20The%20mailflow%20rule%20actually%20look%20in%20the%20email%20%22msip_labels%22%20header%20and%20looks%20for%20the%20specific%20label%20information%20(ex%3A%20%3CEM%3EMSIP_Label_f777f457-ef2d-434d-81b5-0f4123455469_Enabled%3Dtrue%3B).%20%3C%2FEM%3EWhen%20found%20in%20the%20header%2C%20the%20email%20is%20blocked%20and%20a%20notification%20is%20sent%20to%20the%20sender.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20work%20perfectly%20for%20emails%20sent%20from%20Outlook.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20that%20we%20can%20apply%20labels%20with%20Outlook%20on%20the%20Web%20(OWA)%2C%20I%20was%20expecting%20the%20mailflow%20rule%20to%20work%20as%20well%20as%20with%20the%20Outlook%20client.%20It%20does%20not.%20I%20cannot%20understand%20why%20this%20is%20not%20working.%20We%20are%20applying%20the%20same%20label%20to%20the%20email%20in%20OWA%20as%20we%20do%20in%20Outlook.%20We%20can%20see%20in%20the%20message%20header%20that%20the%20%22msip_labels%22%20is%20there%20with%20the%20same%20%3CEM%3EMSIP_Label_f777f457-ef2d-434d-81b5-0f4123455469_Enabled%3DTrue%3B%26nbsp%3B%3C%2FEM%3Einformation.%20The%20only%20difference%20is%20that%20the%20word%20%22True%22%20has%20a%20capital%20%22T%22%20when%20sent%20from%20OWA%20(lowercase%20%22t%22%20when%20sent%20from%20Outlook)%20but%20the%20mailflow%20rule%20are%20not%20case%20sensitive%20anyway.%20Still%2C%20we%20did%20change%20the%20transport%20rule%20to%20also%20have%20a%20capital%20%22T%22%20but%20it%20doesn't%20change%20the%20result.%20When%20looking%20in%20the%20Message%20Trace%20of%20Exchange%20Online%2C%20the%20outgoing%20message%20from%20OWA%20is%20never%20analysed%20by%20the%20mailflow%20rule.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20know%20that%20this%20feature%20(sensitivity%20labels%20in%20Office%20on%20the%20web)%20is%20still%20in%20preview%20but%20I%20was%20wondering%20if%20any%20of%20you%20had%20that%20issue%20or%20would%20have%20an%20idea%20of%20what%20could%20cause%20the%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20your%20help!%3C%2FP%3E%3CP%3E%3CBR%20%2F%3E%3CBR%20%2F%3E.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1012402%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EInformation%20Protection%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESensitivity%20Labels%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1012453%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20block%20emails%20with%20specific%20label%20using%20MailFlow%20rules%20(OWA%20only)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1012453%22%20slang%3D%22en-US%22%3E%3CP%3EActually%2C%20some%20rules%2Fvalues%20are%20case%20sensitive%2C%20which%20might%20explain%20the%20issue.%20Here's%20an%20example%20of%20this%20being%20mentioned%20in%20the%20documentation%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fsecurity-and-compliance%2Fmail-flow-rules%2Fuse-rules-to-bypass-clutter%23use-exchange-online-powershell-to-create-a-mail-flow-rule-to-bypass-the-clutter-folder%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fsecurity-and-compliance%2Fmail-flow-rules%2Fuse-rules-to-bypass-clutter%23use-exchange-online-powershell-to-create-a-mail-flow-rule-to-bypass-the-clutter-folder%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAnd%20yeah%2C%20I%20can%20easily%20find%20other%20articles%20mentioning%20they%20are%20not%20case%20sensitive%2C%20so%20the%20truth%20is%20relative%20it%20seems%20%3A)%3C%2Fimg%3E%20I'll%20try%20pinging%20few%20folks...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1012478%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20block%20emails%20with%20specific%20label%20using%20MailFlow%20rules%20(OWA%20only)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1012478%22%20slang%3D%22en-US%22%3E%3CP%3EOr%20it%20actually%20might%20be%20a%20known%20issue%20for%20OWA%2C%20as%20detailed%20in%20the%20comment%20section%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Finformation-protection%2Fconfigure-exo-rules%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Finformation-protection%2Fconfigure-exo-rules%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1012596%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20block%20emails%20with%20specific%20label%20using%20MailFlow%20rules%20(OWA%20only)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1012596%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BThank%20you%20so%20much%20Vasil.%20That%20seems%20really%20promising%20as%20I%20know%20that%20the%20%22%3B%22%20is%20actually%20configured%20in%20the%20mailflow%20rule.%20I'll%20try%20that%20as%20soon%20as%20I%20can.%3C%2FP%3E%3CP%3EChuck99%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1041252%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20block%20emails%20with%20specific%20label%20using%20MailFlow%20rules%20(OWA%20only)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1041252%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%20Yes%2C%20the%20semicolon%20was%20confirmed%20as%20being%20a%20problem%20for%20Outlook%20on%20the%20web%2C%20and%20is%20now%20removed%20from%20the%20documentation.%20This%20correction%20is%20included%20in%20the%20November%20blog%20post%20for%20doc%20updates%3A%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Information-Protection%2FAzure-Information-Protection-Documentation-Update-for-November%2Fba-p%2F1031924%22%20target%3D%22_self%22%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3EAzure%20Information%20Protection%20Documentation%20Update%20for%20November%202019%3C%2FFONT%3E%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Chuck99
Occasional Contributor

Hi,

 

We have configured a mailflow rules in Exchange Online that will block any email that is labeled with a specific sensitivity label and that is sent outside the organization from being delivered. The mailflow rule actually look in the email "msip_labels" header and looks for the specific label information (ex: MSIP_Label_f777f457-ef2d-434d-81b5-0f4123455469_Enabled=true;). When found in the header, the email is blocked and a notification is sent to the sender.

 

This work perfectly for emails sent from Outlook.

 

Now that we can apply labels with Outlook on the Web (OWA), I was expecting the mailflow rule to work as well as with the Outlook client. It does not. I cannot understand why this is not working. We are applying the same label to the email in OWA as we do in Outlook. We can see in the message header that the "msip_labels" is there with the same MSIP_Label_f777f457-ef2d-434d-81b5-0f4123455469_Enabled=True; information. The only difference is that the word "True" has a capital "T" when sent from OWA (lowercase "t" when sent from Outlook) but the mailflow rule are not case sensitive anyway. Still, we did change the transport rule to also have a capital "T" but it doesn't change the result. When looking in the Message Trace of Exchange Online, the outgoing message from OWA is never analysed by the mailflow rule.

 

I know that this feature (sensitivity labels in Office on the web) is still in preview but I was wondering if any of you had that issue or would have an idea of what could cause the issue.

 

Thank you for your help!



.

4 Replies

Actually, some rules/values are case sensitive, which might explain the issue. Here's an example of this being mentioned in the documentation: https://docs.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/use-rules-to-bypas...

 

And yeah, I can easily find other articles mentioning they are not case sensitive, so the truth is relative it seems :) I'll try pinging few folks...

Or it actually might be a known issue for OWA, as detailed in the comment section here: https://docs.microsoft.com/en-us/azure/information-protection/configure-exo-rules

@Vasil Michev Thank you so much Vasil. That seems really promising as I know that the ";" is actually configured in the mailflow rule. I'll try that as soon as I can.

Chuck99 

@Vasil Michev  Yes, the semicolon was confirmed as being a problem for Outlook on the web, and is now removed from the documentation. This correction is included in the November blog post for doc updates: Azure Information Protection Documentation Update for November 2019 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
30 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies