Jul 01 2022 03:26 AM - edited Jul 01 2022 03:57 AM
Hey Team,
Hoping you can assist here. We have an issue where messages which are "Known Threats" due to the URL, are classified as Phish instead of Malware, and are then placed into quarantine, as Phish messages instead of the Malware messages. THis allows end users to release those messages.
We allow users to release Phish messages, which is usually fine except for this case.
How can we setup Office 365, EOP so that if a messages is infected with a Known Threat, that the message cannot be released, or make it so the message is placed into the Malware Quarantine?
Its important to note that we got these messages over several days, for example we saw messages from 6/28 that were infected and those same messages, still kept coming in on 6/30, and were still placed into the Phish queue and not the malware queue. Same Phish URL etc.
Office 365 is our only messaging filtering service, and is the Endpoint for our MX records. We have E1 with the EOP Add ons. All mailboxes are in the cloud.
Thanks,
Robert
Jul 05 2022 09:06 AM