Not really a question, but found out the hard way that the default outbound spam policy setting of "Restrict the user from sending mail till the following day" does NOT allow admin override when a user triggers the policy.  Nor does the affected user account show in the Restricted Users portal (nor powershell query: Get-BlockedSenderAddress).  Which means the user is effectively blocked from sending email until the next day with no option to remove the restriction. 


This seems like an undesirable outcome (not to mention default behavior).  It would seem like a better option would be to block for a day, but allow an admin to override and remove the restriction if desired.  Of course the other policy option (which I will universally recommend going forward) is to use "Restrict the user from sending mail" instead which would always require manual intervention (but at least that's an option).  


Probably won't affect many orgs since I suspect most keep the service defaults of 10000 emails to trigger the policy, but for any orgs that fine tune to a more effective level it just seems weird and unexpected to me.   Am I missing something?


Here's the MS doc documenting/verifying the behavior: https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/configure-the-outbound-s...



