Mar 21 2023 02:19 AM
Hi all. We have been using preset policies (standard and strict) for some time and were happy with the fact that they don't notify users of messages which have been quarantined (and nor is it possible to change the notification policy). However, quarantine notifications suddenly started turning up in users' mailboxes at the weekend.
Have Microsoft changed something or released an unplanned change? Hoping you can help clarify the situation.
Jul 04 2023 10:23 PM
@AnonTechSpecialist I understand. I don't have an ETA on when we will address this but certainly agree with the ask and is top of mind for us.
Jul 25 2023 05:13 AM
@OzOscroft I can't believe how dumbfoundingly stupid this change is. It opens the quarantine up to inexperienced users and LOWERS my security and it defeats the purpose of having the rules by spamming my users with "you have spam" emails.
It's time to start looking at moving the company to another platform for mail.
Jan 17 2024 08:50 AM
@OzOscroft
The only way I've found to prevent users from being notified about quarantined messages is to disable the "Standard Protection" policy:
Once you do that, your custom policies are now the priority and the other policies go back into effect:
It's a "use at your own risk" scenario, which is unfortunate. I think it will also lower your Microsoft "Secure Score" if that's a metric you track. I'm still doing some reading to see if it affects any other components of the M365 Security system.
I would strongly prefer to be able to use Microsoft's recommended Standard or Secure preset security policies without having to worry that the end users will undermine the whole thing by releasing malicious messages into their mailboxes, but that isn't currently possible. 😞
Jan 17 2024 08:54 AM
Jan 22 2024 09:32 AM
@kleveille The other solution I found is that continuing to use O365 was becoming a liability. From the wide onmicrosoft.com domain allowing bots to spam us and flooded my users with these unwanted messages we moved our entire operation to GSuite. It's cut my operation costs to maintain email by at least half and not getting nearly as much spam from Microsoft's own domains.