Malware Policy
By default, the Microsoft Teams malware policy scans for malicious content in the files sent using Microsoft Teams.
Supported Actions
Microsoft Teams malware policy supports these actions:
-
Tombstone of files and text messages that contain malicious content.
-
If malicious content is found, the sender will get the tombstoned message.

For information about unblocking the tombstoned message, see Unblocking Messages.
-
If malicious content is found, the recipient(s) will get the tombstoned message.

-
Alert sender: Sends an email notification to the sender of a file or message that contains malicious content.
-
Alert admin(s): Sends an email notification to the admin(s) about the malicious files or messages.
Configuring Malware Policy
-
Click Policy on the left panel of the Avanan
Administrator Portal.
-
Click Add a New Policy Rule.
-
From the Choose SaaS drop-down list, select Microsoft Teams.
-
From the Choose Security drop-down list, select Malware and click Next.
-
Select the desired protection mode (Detect and Remediate or Detect).
If required, you can change the Rule Name.
-
Under Blades, select the threat detection blades required for the policy.
Note: To select all the blades available for malware detection, enable All running threat detection blades checkbox.
-
Configure Actions required from the policy.
-
To tombstone messages, enable the Tombstone Message checkbox.
Note: This option will be available only in Detect and Remediate protection mode and when URL Reputation threat detection blade is enabled.
-
To tombstone files, enable the Tombstone File checkbox.
Note: This option will be available only in Detect and Remediate protection mode and when the Anti-Malware threat detection blade is enabled.
-
To send email alerts to the sender about malware in messages and files, enable the Alert sender - messages and Alert sender - files checkbox.
-
To send email alerts to admins about malware in messages and files, enable the Alert admin(s) - messages and Alert admin(s) - files checkbox.

-
Click Save and Apply.