Excluding Members of Microsoft 365 Groups from a Prevent (Inline) Policy
When you exclude a user from a policy in the Prevent (Inline) protection mode, this is the expected behavior:
-
The excluded user's emails will not be processed by Avanan using the Prevent (Inline) protection mode.
-
The policy workflow in Prevent (Inline) protection mode will not apply to the excluded user.
However, these factors might affect this expected behavior:
-
If the excluded user is a member of a Microsoft 365 group that includes other users protected by a Prevent (Inline) policy.
-
If the email is sent to other users who are protected by a Prevent (Inline) policy.
Scenarios and Expected Behavior for Excluded Users in Prevent (Inline) Policies:
|
Email sent only to the excluded user |
Email sent to excluded user and another protected user |
Email sent to group |
||||
|---|---|---|---|---|---|---|
|
Policy protection mode |
Workflows applied? |
Policy protection mode |
Workflows applied? |
Policy protection mode |
Workflows applied? |
|
|
Excluded user is part of a protected Microsoft 365 group |
Prevent (Inline) |
No |
Prevent (Inline) |
Yes |
Prevent (Inline) |
Yes |
|
Excluded user is part of another protected group (not Microsoft 365) |
Detect |
No |
Detect |
No |
Detect |
No |
|
Excluded user is not part of any protected group |
Detect |
No |
Detect |
No |
Detect |
No |
Example:
Consider a policy in Prevent (Inline) protection mode with these settings:
-
The policy applies to all users except John Smith.
-
The policy workflow is configured to quarantine phishing emails.
-
John Smith is part of a Microsoft 365 group with James Wilson.
Scenario 1: A phishing email is sent only to John Smith (excluded user)
Result: The email was inspected and identified as phishing but delivered to John Smith's mailbox since the Prevent (Inline) policy was not applied, and the email was not quarantined.
Scenario 2: A phishing email is sent to both John Smith (excluded user) and James Wilson (protected user)
Result: The email was inspected, identified as phishing, and quarantined. John Smith's email was not delivered, though he was excluded from the policy.
Scenario 3: A phishing email is sent to John Smith and James Wilson (both part of a protected Microsoft 365 group)
Result: The email was inspected, identified as phishing, and quarantined. Both John Smith and James Wilson do not receive the email.
Scenario 4: A phishing email is sent to John Smith and James Wilson (both John Smith and James Wilson were part of a different group type
Result: The email was inspected and identified as phishing. The email is delivered to John Smith's mailbox without being quarantined.