Sophos Email customers using IP-based mailflow rule connectors must migrate to certificate-based configuration by March 31st. To see if you're affected Click Here.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

MS 365 Alerts ETR override as Sophos passes along phishing attacks

We've always gotten a lot of phishing attacks since we started on Sophos Email Protection. Maybe slightly less than when we just had the standard MS365 spam protection. I collect many of the blatant ones that get through, which is at least once a day. And our users use the Report Message button to report to Sophos. To implement Sophos we are supposed to have a rule in place to pass all mail (Sophos doc refers to it as "clean" mail) from Sophos to the user.

The last few weeks we have been getting alerts from MS 365: "Informational-severity alert: Phish delivered due to an ETR override". This is alerting us to the fact that the Sophos EOP override rule has forced MS 365 to pass along a phishing email to us. So with each phishing email, I get to go through a bunch of emails:

--2 or 3 people asking me if the message is OK

--1-3 people reporting via Sophos

-- And now, multiple alerts from MS telling me their basic email protection service can see it's a phish but the advanced Sophos tool can't--an alert for each user that gets the phish, which usually is several.

I don't want to turn off alerts from MS, but I also don't need alerts from MS telling me what I know (that a phishing email was let through by Sophos).

Anyone know why this started in last few weeks? Anyone know how to turn it off for just one ETR rule?

Mitch Turner

Sr. Director, IT, NDIA



Edited tags
[edited by: Raphael Alganes at 6:31 AM (GMT -7) on 7 Jun 2023]
Parents
  • Hello there,

    Thank you for contacting the Sophos Community.

    I would recommend you to get a case open with support, and submit the email samples directly to the engineer, so they can pass them down directly to our Labs Team.

    Checking internally I noticed an open case for the same, on Sep 1 after the samples were submitted to Labs,  they mentioned they aren’t Phish but rather Spam.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • I got an answer from the engineer within a day that our system was configured correctly and they would be looking at the submitted samples. A week later I got an update asking if we had any updates on the issue. We were waiting for some answer on why the samples got through. Yesterday we got a response to my response saying they were looking at the samples. We continue to have fresh examples of clear phishing attacks almost every day. Hoping we get a specific response on these, this really goes to the heart of the email protection product.

Reply
  • I got an answer from the engineer within a day that our system was configured correctly and they would be looking at the submitted samples. A week later I got an update asking if we had any updates on the issue. We were waiting for some answer on why the samples got through. Yesterday we got a response to my response saying they were looking at the samples. We continue to have fresh examples of clear phishing attacks almost every day. Hoping we get a specific response on these, this really goes to the heart of the email protection product.

Children
  • Here is the response from Sophos Support Team.

    The samples submitted are a part of new zero-day campaign and we have update our detection level to block them. This will help block the similar type of samples and will not come again.

    My confidence in this product just went down a couple of notches. For a product that is suppose to be more superior than the built in MS Tools. Why am I even paying for this...

  • Wow. I've given 30 samples, can give hundreds more. They are mostly the standard "invoice due", "voicemails waiting", "your account will be deleted" type things. If I get an answer like that it's time to move to a different service. Obviously Microsoft can catch at least some of them--and that is with their basic protection. I'm guessing the advanced protection will be even better.

  • Hello Mitch,

    Thank for the feedback, I have asked the engineer to check the rest of the emails, as a couple of them seem to be released by the user from their quarantine.

    In any case for the ones that weren’t caught the engineer will be checking with our Senior Internal team.

    If you receive any new "phish" email from your users, would it be possible for you to send me a couple to me directly via PM. 

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.