tmoon-mint Posted February 14, 2022 Posted February 14, 2022 Hi all, At the moment we have mail rules setup to target things such as BTC wallet addresses, file attachments etc and these are then sent to the hosted quarantine. Staff are notified when messages are quarantined and if they request it I then check the messages for false positives and release as necessary. I have had the request for staff to be able to release their own messages, with the user stating that they used to be able to do this at their old work place. Personally I think this is a bad idea but I have agreed to look into it. From what I can tell this would require access to Microsoft 365 Defender which I dont believe comes included with A1 Plus for Faculty which is the license staff are currently on. Could anyone advise on this please? Also can anyone else advise me how they deal with quarantined messages currently? Do you allow admins to release the messages or do staff do it themselves? Thanks, Tom
free780 Posted February 14, 2022 Posted February 14, 2022 Very much depends on what the mail is classed as: This is a balance between security and user choice. I think when just using EOP (No 365 Defender) you can set the Junk Mail as the destination which would fulfil the need. The worry is a e-mail that classed as spam could be phishing. Malware - Admin Only Quarantine Spam - Junk Mail High Confidence Spam - Junk Mail High Confidence Phishing - Admin Only Quarantine Bulk - No Action (User can mark as Junk) 1
Boredguy Posted February 14, 2022 Posted February 14, 2022 Our users who have standard A1 Plus licences have been able to release messages from Quarantine without our intervention (and we don't have a Defender licence) In the daily notification e-mail should be the link to https://security.microsoft.com/quarantine where they should just see their messages to release/delete 1
tmoon-mint Posted February 14, 2022 Author Posted February 14, 2022 Our users who have standard A1 Plus licences have been able to release messages from Quarantine without our intervention (and we don't have a Defender licence) In the daily notification e-mail should be the link to https://security.microsoft.com/quarantine where they should just see their messages to release/delete Thanks for this. I need to look into our configuration then. When I navigate to that link as a standard user I get an error and the messages dont load. Thanks.
tmoon-mint Posted February 14, 2022 Author Posted February 14, 2022 Found it. I have it setup currently so end users cannot access quarantine which explains why they get an error message when going to https://security.microsoft.com/quarantine Its under threat policies in the security and compliance centre if anyone else is looking for it. Thanks again all.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now