Microsoft Quarantined emails and 'Machine learning'

Dan Johnson 26 Reputation points
2021-03-03T18:16:03.68+00:00

Hi

We have an issue in our organisation and we are struggling along with Microsoft support re a solution.

We send phishing emails and in particular impersonation emails to quarantine.

We have users who have created personal accounts that match the name of their organisational accounts. So jxx@Karima ben .com send email to jxx@corporateaccont.com

Now the system is doing its job here and these emails are being flagged as CAT UIMP or GIMP etc and the emails are sent to quarantine. So far so good.

Now as these emails are genuine we have raised with Microsoft and asked the best way to allow genuine impersonation emails to land in the users inbox. Microsoft have advised that the user should release the email, submit it to Microsoft and reply back and forth and the machine will 'learn' and eventually emails from Jxx@Karima ben .com sent to jxx@corporateaccont.com will no longer be quarantined.

This is true to an extent. If Jxx releases one of these emails he is able to reply back and forth within that email conversation with no issues.

If however a fresh email is sent from Jxx@Karima ben .com sent to jxx@corporateaccount.com this will still hit quarantine. No matter how many times we release and submit we can never get a new email to bypass quarantine.

So it looks like this machine is not fully learning.

We have been advised by non microsoft folk that users can simply add the personal account to their safe sender list and this resolves the issue. My business has rejected this as they dont want any bypasses in place. They want the system to 'learn'

My question is when we add users to safe sender list does this bypass the full protection stack?

Are we being naïve as to expect the system to learn in this way?

Does anyone have any experience with this and the best way to approach it? Other than telling users not to create personal accounts and send to their corporate accounts?

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,360 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 142.3K Reputation points MVP
    2021-03-03T18:29:59.7+00:00

    Well, I would was going to say "telling users not to create personal accounts and send to their corporate accounts" haha

    In these instances, we typically tell users to simply add to their safe senders list . It does bypass some of the filtering stack when you do this - except malware and high confidence phishing, however its not much different IMO than ATP learning since the ML should be applying that only to the mailbox in question. From what I have seen, the machine learning only goes so far - and there is also an element of time here and the need to communicate and not wait for the ML to kick in and creating multiple transport rules versus using safe sender lists is going to be a never-ending moving target.

    Im sure you have seen this already:
    https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/create-safe-sender-lists-in-office-365?view=o365-worldwide

    0 comments No comments