Sheridan Posted June 11, 2024 Posted June 11, 2024 I'm trying to use the Exchange 365 Advanced Hunting to trace (and delete) a phishing email. In true MS form this doesn't seem to work but offers little help! If I select an email and use the 'Go Hunt' option, it opens the Advanced Hunting window but with an error 'Failed to decode shared query text' and I can see the query shows an error status - but it looks like the schema it needs (EmailEvents) is missing from the list of schemas I have - how do I add missing schemas, or is this some licensing issue? (we're on A3 for Faculty)
andy_b Posted June 11, 2024 Posted June 11, 2024 Doesn't help with this - but I mostly use Content Search and powershell to remove phishing emails - https://learn.microsoft.com/en-us/purview/ediscovery-search-for-and-delete-email-messages 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now