This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Phish Threat emails quarantined by Microsoft despite listed as Phishing Simulation Exemptions Under Advanced Delivery

Hello,

As the above title suggests.

We are trialling the Sophos Phish Threat service. I have added in exceptions for the domains and IPs used by the Phish Threat service to the Phishing simulation tab within the Advanced Delivery section of the Microsoft 365 Defender portal. However, emails are still being quarantined by Microsoft.

If I add in my address to the SecOps Mailbox section, the emails come through just fine. The same can't be said for the exceptions made to the origin, i.e. the domains and IPs used by the Sophos Phish Threat service.

Please advise.



This thread was automatically locked due to age.
Parents
  • For anyone else experiencing this, a new feature was added to Phish Threat that bypasses M365's filters for the Phish Threat emails only - per Sophos - which resolved this for us. You can find this in Phish Threat > Settings > M365 Direct Delivery.

Reply
  • For anyone else experiencing this, a new feature was added to Phish Threat that bypasses M365's filters for the Phish Threat emails only - per Sophos - which resolved this for us. You can find this in Phish Threat > Settings > M365 Direct Delivery.

Children
No Data