Enabling end-user Quarantine email notification - Microsoft Exchange Online

 Hello All

Today we are going to see, how m365 exchange admin can enable the and  end-user spam notification messages lets our users manage their own quarantined spam, bulk, and phishing messages.

quarantine holds potentially dangerous or unwanted messages.


Quarantine notifications aren't turned on in the default quarantine notifications named AdminOnlyAccessPolicy or DefaultFullAccessPolicy

By default, messages that are quarantined as high confidence phishing by anti-spam policies, malware by anti-malware policies or Safe Attachments, or by mail flow rules (also known as transport rules) are available only to admins.

The old school method has gone now to configure the end-user spam notification messages which was available in exchange admin centre. Now its moved to defender portal with improved settings and configurations

Let us go and enable it in step by step 

Login into the security 

https://security.microsoft.com/

Under Policies and Rules --> Threat Polices --> Quarantine Policy


Create new quarantine Policy by click "Add Custom policy"



According to your business needs , select your options





Review all the summary before submit



Policy has been created , now its time to enable the custom policy in all appropriate threat policies, like Anti spam, Anti malware, Anti Phishing, wherever its applicable
 





The Global Settings

Admins can configure the below from the global settings

  • Quarantine Sender Email address 
  • Quarantine Sender Display Name
  • Subjects
  • Disclaimer
  • Languages
  • Number of days to send the notifications






Once we set the custom policy in the appropriate threat polices. we test whole scenario by sending one test  email with help of  EICAR file  - G TUBE the Generic Test for Unsolicited Bulk Email.

If your spam filter supports it, the GTUBE provides a test by which you can verify that the filter is installed correctly and is detecting incoming spam, in a similar fashion to the EICAR anti-virus test file.

Spam filter developers should add a rule, where possible, to recognise the following 68-byte string in the message body, and trigger on it:

  XJS*C4JDBQADN1.NSBN3*2IDNEN*GTUBE-STANDARD-ANTI-UBE-TEST-EMAIL*C.34X


How is works

Compose  a email with body of the below code

XJS*C4JDBQADN1.NSBN3*2IDNEN*GTUBE-STANDARD-ANTI-UBE-TEST-EMAIL*C.34X





End User experience 

Let us see how end user see the notification of quarantine emails

End user will get notify like below, in either outlook or OWA , if any any the emails gets quarantine due to some reason




Once the end user click the Quarantine Page Link from his email , he will get the below page redirect to quarantine page, in which he can take the action accordingly 


Release the email





Delete the emails



Message Preview from Quarantine




I hope you enjoyed this topics and learned something new. Happy Learning ๐Ÿ™‚ 

Comments