Jump to content

Recommended Posts

Posted

Hi all,

 

Scratching my head on this one. I have setup a quarantine policy in the MS365 securty centre allowing end users to check their own messages and request them to be released.

 

At the moment they can only see messages that are quarantined by the anti spam policy and not messages quarantined using the exchange rules I have setup (to block HTML attachments, any mention of crypto and dodgy looking links) what am I doing wrong?

Posted

There should be a policy that sets what users can, and can't, do. I think the options are just be informed, view, and release.

 

I'll have a poke around and see if I can find it as I never remember where stuff is in the portal now.

Posted
What you have described is basically how we are setup, things may have changed but we could only generate quarantine release emails from messages quarantined by one of Microsofts policies. Anything we created a manual rule for, we just simply had a plain text email sent to the recipient saying you have had a message go to quarantine for X, please contact ICT support if you need this message.
Posted (edited)

So in security.microsoft.com go to Policies & rules > Threat policies > Quarantine policy.

 

You can then create policies for different things and set what access they have and what notification they get.

 

Then in Policies & rules > Threat Policies you can create a policy for each category and assign a quarantine policy.

 

EDIT: Ahh, sorry, didn't read properly and see that it is custom rules you were talking about. As far as I am aware, as long as the rule sends it to quarantine then the quarantine rules apply.

Edited by TechMonkey
Posted

Argh that sucks. I am trying to reduce the number of tickets we get asking for us to check a message to see if its genuine because 9/10 its an obvious phish.

 

This is how my rules are setup. Could anyone share how they do it?

Screenshot 2023-05-17 at 11.04.15.png

Posted
Having had a look, it is the same quarantined area, so you could put a link to it and ask staff to check themselves in the notification email. Otherwise, as long as you have a quarantine policy setup, it will appear in their normal notification.
Posted

The link I am providing is security.microsoft.com/quarantine hopefully this is correct.

 

The emails detected by the Microsoft policies work fine, any quarantined by rule only show up for admins.

Posted

I used the built in strict policy in office 365, now teachers get a summary email (next day) with the subject of every quarantine email and can view it online or release it.

 

(no I can't remember where this was, probably exchange)

  • 3 weeks later...
Posted
So I have sorted this. Most of the messages being sent to quarantine via exchange rules can be done by Defender instead so I have just changed my setup. Any rules that use a regex like the crypto one still cant be checked and released by staff but to be honest I kind of feel like thats a good thing.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...