EOP International spam option

%3CLINGO-SUB%20id%3D%22lingo-sub-856994%22%20slang%3D%22en-US%22%3EEOP%20International%20spam%20option%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-856994%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20we%20configure%20the%20EOP%20international%20spam%20GEO%20location%20setting%2C%20is%20there%20any%20way%20to%20allow%20specific%20IP%20address%20from%20defined%20location%20without%20bypassing%20other%20content%20filter%20%2F%20ATP%20scanning%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-856994%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EEOP%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EGEO%20filtering%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-857327%22%20slang%3D%22en-US%22%3ERe%3A%20EOP%20International%20spam%20option%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-857327%22%20slang%3D%22en-US%22%3E%3CP%3EI%20guess%20you%20can%20add%20them%20in%20the%20Allowed%20IP%20lists%20under%20your%20connection%20filter%20policy%2C%20then%20use%20a%20transport%20rule%20to%20set%20the%20SCL%20to%200%20and%20force%20them%20to%20be%20rescanned%20by%20the%20content%20filter.%20Detailed%20instructions%20for%20example%20here%3A%26nbsp%3B%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2FSecurityCompliance%2Fconfigure-the-connection-filter-policy%23scoping-an-ip-allow-list-exception-for-a-specific-domain%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2FSecurityCompliance%2Fconfigure-the-connection-filter-policy%23scoping-an-ip-allow-list-exception-for-a-specific-domain%3C%2FA%3E%3C%2FFONT%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-857376%22%20slang%3D%22en-US%22%3ERe%3A%20EOP%20International%20spam%20option%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-857376%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BJust%20want%20to%20make%20sure%2C%20how%20EOP%20is%20processing%2C%20is%20it%20applying%20ETR's%20first%20or%20spam%20protection%2Fcontent%20filtering%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-858514%22%20slang%3D%22en-US%22%3ERe%3A%20EOP%20International%20spam%20option%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-858514%22%20slang%3D%22en-US%22%3E%3CP%3EDifferent%20anti-spam%20features%20are%20processed%20at%20different%20stages%2C%20see%20for%20example%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fsecuritycompliance%2Feop%2Fexchange-online-protection-overview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fsecuritycompliance%2Feop%2Fexchange-online-protection-overview%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

If we configure the EOP international spam GEO location setting, is there any way to allow specific IP address from defined location without bypassing other content filter / ATP scanning?

3 Replies
Highlighted

I guess you can add them in the Allowed IP lists under your connection filter policy, then use a transport rule to set the SCL to 0 and force them to be rescanned by the content filter. Detailed instructions for example here: https://docs.microsoft.com/en-us/office365/SecurityCompliance/configure-the-connection-filter-policy...

Highlighted

@Vasil Michev Just want to make sure, how EOP is processing, is it applying ETR's first or spam protection/content filtering?

Highlighted

Different anti-spam features are processed at different stages, see for example here: https://docs.microsoft.com/en-us/office365/securitycompliance/eop/exchange-online-protection-overvie...