SOLVED

Quality of Exchange Online Protection

%3CLINGO-SUB%20id%3D%22lingo-sub-9313%22%20slang%3D%22en-US%22%3EQuality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-9313%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20currently%20run%20a%20third%20party%20antispam%20solution%20in%20front%20of%20Exchange%20Online%20and%20find%20that%20we%20don't%20get%20much%20spam%20in%20our%20mail%20boxes.%20Now%20the%20agreement%20on%20this%20third%20party%20solution%20is%20up%20for%20renewal%20and%20it%20prompts%20the%20question%20of%20whether%20this%20is%20necessary%20at%20all.%20Can%20we%20just%20use%20Exchange%20Online%20Protection%20or%20will%20we%20start%20getting%20lots%20of%20spam%20and%20malware%20delivered%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat's%20the%20opinion%20and%20the%20experience%20of%20people%20running%20just%20EOP%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-186680%22%20slang%3D%22en-US%22%3ERe%3A%20Quality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-186680%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20deploy%20EOP%20as%20well%20as%20advanced%20threat%20protection.%20The%20malware%20filters%20and%20ZAP%20are%20good%2C%20and%20safe%20attachments%20works%20well%2C%20but%20we%20find%20safelinks%20fails%20for%20the%20majority%20of%20phishing%20stuff%20that%20makes%20it%20through.%20and%20we%20also%20have%20to%20supplement%20the%20filter%20with%20transport%20rules%20to%20catch%20a%20lot%20of%20phishing%20material%20that%20makes%20it%20through%20due%20to%20the%20phishers%20doing%20due%20diligence.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-181731%22%20slang%3D%22en-US%22%3ERe%3A%20Quality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-181731%22%20slang%3D%22en-US%22%3E%3CP%3EDavid%2C%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20a%20lot%20for%20update.%20We%20are%20already%20working%20with%20MS%20team%20and%20definitely%20seeing%20lots%20of%20benefits%20and%20new%20features.%26nbsp%3B%3CBR%20%2F%3Eregards%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-181444%22%20slang%3D%22en-US%22%3ERe%3A%20Quality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-181444%22%20slang%3D%22en-US%22%3E%3CP%3EVictor%2C%3C%2FP%3E%3CP%3EDefinitely%20a%20lot%20of%20changes%20in%20the%20last%20few%20months%20and%20all%20for%20the%20better.%26nbsp%3B%20EOP%20and%20ATP%20(add-on%20or%20E5)%20have%20been%20adding%20features%20and%20protection.%26nbsp%3B%20While%20I%20am%20saying%20it%20is%20far%20better%2C%20I%20do%20recommend%20you%20engage%20your%20Microsoft%20Account%20team%20for%20better%20and%20more%20accurate%20informations.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPhishing%20is%20a%20new%20tag%20in%20the%20headers%2C%20and%20EOP%20has%20sensing%20it%20better%20and%20sending%20to%20Junk%2FQuarantine.%26nbsp%3B%26nbsp%3B%20More%20features%20are%20being%20added%20to%20GUI%20based%20programming%20and%20away%20from%20Transport%20rules%20making%20it%20easier%20to%20administer.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELastly%2C%20the%20newly%20updated%20Security%20And%20Compliance%20Center%20have%20added%20a%20lot%20of%20features%20for%20EOP%20and%20ATP.%26nbsp%3B%20Reporting%20has%20also%20increased%20with%20more%20realtime%20reports%20than%20previous.%26nbsp%3B%20All%20in%20all%2C%20lets%20of%20improvement%20in%206plus%20months%20and%20worth%20looking%20it.%20-%20David%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-181232%22%20slang%3D%22en-US%22%3ERe%3A%20Quality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-181232%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CBR%20%2F%3Ethank%20you%20for%20the%20detailed%20answer.%20We%20are%20basically%20at%20the%20same%20point%20right%20now%20and%20thinking%20if%20we%20need%20a%20third%20party%20or%20not.%26nbsp%3B%20Since%20topic%20is%20~about%202%20years%20old%20I%20would%20like%20to%20know%20what%20changes%20are%20there.%3CBR%20%2F%3EThank%20you%20in%20advance%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-13812%22%20slang%3D%22en-US%22%3ERe%3A%20Quality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-13812%22%20slang%3D%22en-US%22%3E%3CP%3EFor%20mail%2C%20EOP%20is%20very%20good%20and%20doing%20the%20job.%26nbsp%3B%20Make%20sure%20to%20learn%20about%20Transport%20Rules.%26nbsp%3B%20Experience%20in%20REGEX%20is%20a%20plus%20enabling%20you%20to%20create%20moe%20challenging%20Rules.%3C%2FP%3E%3CP%3ESPAM%20filter%20has%20recently%20been%20improved%20with%20known%20attachments%20filter.%20Now%2C%20you%20can%20quickly%20and%20easily%20block%2096%20known%20attachments.%26nbsp%3B%20If%20you%20want%20others%2C%20use%20the%20transport%20rules.%3C%2FP%3E%3CP%3EMalware%20filter%20is%20excellant%2C%20but%20like%20everything%20else%2C%20zero%20day%20is%20still%20a%20challenge%20although%20EOP%20seems%20to%20catch%20up%20quickly%3C%2FP%3E%3CP%3EZAP%20is%20my%20favorite.%26nbsp%3BMail%20(even%20that%20which%20has%20been%20delivered%20to%20Inbox)%20is%20continously%20and%20dynamically%20protected.%26nbsp%3B%20If%20the%20reputaton%20of%20a%20sender%20exceeds%20limits%2C%20and%20the%20mail%20has%20not%20yet%20been%20read%2C%20it%20moves%20it%20out%20of%20Inbox%20into%20Junk.%3C%2FP%3E%3CP%3ECombine%20all%20of%20this%20with%20SCL%20setting%2C%20Personal%20Quarantine%20(user%20viewable)%20and%20System%20Quarantine%20(admin%20only)%20and%20it%20is%20doing%20its%20job.%3C%2FP%3E%3CP%3EUsing%20another%20vendor%20as%20desktop%2Fserver%20protection%20will%20enhance%20your%20security%20umbrella.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%2C%20make%20no%20mistake%2C%20you%20need%20to%20do%20your%20part%20and%20learn%2Fadminister%20it%20all%20-%20David%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-9945%22%20slang%3D%22en-US%22%3ERe%3A%20Quality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-9945%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EEOP%20works%20fine%20for%20our%20customers.%20And%20if%20they%20want%20(extra)%20protection%20against%20zero-day%20exploits%20have%20a%20look%20at%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fproducts.office.com%2Fen-us%2Fexchange%2Fonline-email-threat-protection%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fproducts.office.com%2Fen-us%2Fexchange%2Fonline-email-threat-protection%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-9811%22%20slang%3D%22en-US%22%3ERe%3A%20Quality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-9811%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%2C%20Rick%20and%20Paul.%20This%20is%20very%20interesting%20and%20it%20seems%20like%20we%20can%20do%20without%20the%20third%20party%20solution.%20We'll%20try%20it%20out%20and%20see%20if%20it%20works.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-9453%22%20slang%3D%22en-US%22%3ERe%3A%20Quality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-9453%22%20slang%3D%22en-US%22%3EI%20too%20have%20seen%20EOP%20catch%20things%20even%20after%20it%20has%20gone%20through%20a%20Barracuda%20filter.%20I%20do%20want%20to%20say%20that%20it%20would%20not%20surprise%20me%20to%20have%20a%20Barracuda%20catch%20a%20few%20things%20after%20going%20through%20EOP%20either%20though.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-9452%22%20slang%3D%22en-US%22%3ERe%3A%20Quality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-9452%22%20slang%3D%22en-US%22%3E%3CP%3EI%20believe%20it%20provides%20a%20solid%20alternative%20to%20most%20solutions%20on%20the%20market%20right%20now%2C%20but%20like%20any%20anti-spam%20solution%2C%20they%20are%20hard%20to%20compare%20apples%20to%20apples.%20One%20of%20our%20biggest%20challenges%20right%20now%20with%20EOP%20is%20ensuring%20it%20meets%20the%20client%20requirements%20in%20order%20to%20move%20away%20from%20their%20in%20place%20solution.%20While%20EOP%20is%20a%20fully%20fledged%20product%2C%20they%20are%20still%20adding%20capabilities%20to%20it%20that%20other%20competitors%20already%20have%20in%20place.%20If%20EOP%20meets%20your%20requirements%2C%20I%20would%20say%20it%20is%20well%20worth%20the%20switch%20as%20you%20are%20already%20paying%20for%20it.%20If%20there%20is%20a%20hard%20requirement%20for%20a%20feature%20that%20your%20current%20product%20has%2C%20you%20may%20have%20to%20stick%20with%20it%20for%20a%20bit%20longer%2C%20but%20MS%20is%20adding%20capabilities%20all%20the%20time.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-9331%22%20slang%3D%22en-US%22%3ERe%3A%20Quality%20of%20Exchange%20Online%20Protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-9331%22%20slang%3D%22en-US%22%3E%3CP%3EWe've%20been%20using%20Exchange%20Online%20with%20it's%20built-in%20protection%20for%20nearly%20a%20year%20and%20a%20half%20now%20without%20any%20additional%20third-party%20anti-spam%20service%20and%20I'm%20quite%20pleased%20with%20it.%26nbsp%3B%20We're%20a%20mid-sized%20government%20agency%2C%20and%20before%20going%20to%20Exchange%20Online%20we%20ran%20a%20pair%20of%20on-prem%20Barracuda%20Spam%20Firewall's%20which%20did%20a%20very%20good%20job%20of%20catching%20and%20filtering%20spam.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20really%2C%20EOP%20is%20one%20of%20the%20better%20features%20with%20Office%20365.%26nbsp%3B%20We've%20actually%20seen%20a%20reduction%20from%20the%20Barracuda%20in%20what%20actually%20gets%20through.%26nbsp%3B%20It's%20been%20nice.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Deleted
Not applicable

We currently run a third party antispam solution in front of Exchange Online and find that we don't get much spam in our mail boxes. Now the agreement on this third party solution is up for renewal and it prompts the question of whether this is necessary at all. Can we just use Exchange Online Protection or will we start getting lots of spam and malware delivered?

 

What's the opinion and the experience of people running just EOP?

10 Replies
Highlighted

We've been using Exchange Online with it's built-in protection for nearly a year and a half now without any additional third-party anti-spam service and I'm quite pleased with it.  We're a mid-sized government agency, and before going to Exchange Online we ran a pair of on-prem Barracuda Spam Firewall's which did a very good job of catching and filtering spam.

 

But really, EOP is one of the better features with Office 365.  We've actually seen a reduction from the Barracuda in what actually gets through.  It's been nice.

Highlighted

I believe it provides a solid alternative to most solutions on the market right now, but like any anti-spam solution, they are hard to compare apples to apples. One of our biggest challenges right now with EOP is ensuring it meets the client requirements in order to move away from their in place solution. While EOP is a fully fledged product, they are still adding capabilities to it that other competitors already have in place. If EOP meets your requirements, I would say it is well worth the switch as you are already paying for it. If there is a hard requirement for a feature that your current product has, you may have to stick with it for a bit longer, but MS is adding capabilities all the time. 

Highlighted
I too have seen EOP catch things even after it has gone through a Barracuda filter. I do want to say that it would not surprise me to have a Barracuda catch a few things after going through EOP either though.
Highlighted

Thank you, Rick and Paul. This is very interesting and it seems like we can do without the third party solution. We'll try it out and see if it works.

 

 

Highlighted

EOP works fine for our customers. And if they want (extra) protection against zero-day exploits have a look at https://products.office.com/en-us/exchange/online-email-threat-protection

Highlighted
Best Response
Solution

For mail, EOP is very good and doing the job.  Make sure to learn about Transport Rules.  Experience in REGEX is a plus enabling you to create moe challenging Rules.

SPAM filter has recently been improved with known attachments filter. Now, you can quickly and easily block 96 known attachments.  If you want others, use the transport rules.

Malware filter is excellant, but like everything else, zero day is still a challenge although EOP seems to catch up quickly

ZAP is my favorite. Mail (even that which has been delivered to Inbox) is continously and dynamically protected.  If the reputaton of a sender exceeds limits, and the mail has not yet been read, it moves it out of Inbox into Junk.

Combine all of this with SCL setting, Personal Quarantine (user viewable) and System Quarantine (admin only) and it is doing its job.

Using another vendor as desktop/server protection will enhance your security umbrella.

 

But, make no mistake, you need to do your part and learn/administer it all - David

Highlighted

Hello 
thank you for the detailed answer. We are basically at the same point right now and thinking if we need a third party or not.  Since topic is ~about 2 years old I would like to know what changes are there.
Thank you in advance

Highlighted

Victor,

Definitely a lot of changes in the last few months and all for the better.  EOP and ATP (add-on or E5) have been adding features and protection.  While I am saying it is far better, I do recommend you engage your Microsoft Account team for better and more accurate informations.

 

Phishing is a new tag in the headers, and EOP has sensing it better and sending to Junk/Quarantine.   More features are being added to GUI based programming and away from Transport rules making it easier to administer.

 

Lastly, the newly updated Security And Compliance Center have added a lot of features for EOP and ATP.  Reporting has also increased with more realtime reports than previous.  All in all, lets of improvement in 6plus months and worth looking it. - David

Highlighted

David, 

Thanks a lot for update. We are already working with MS team and definitely seeing lots of benefits and new features. 
regards  

Highlighted

We deploy EOP as well as advanced threat protection. The malware filters and ZAP are good, and safe attachments works well, but we find safelinks fails for the majority of phishing stuff that makes it through. and we also have to supplement the filter with transport rules to catch a lot of phishing material that makes it through due to the phishers doing due diligence.