Excluding Members of Microsoft 365 Groups from a Prevent (Inline) Policy

When you exclude a user from a policy in the Prevent (Inline) protection mode, this is the expected behavior:

  • The excluded user's emails will not be processed by Avanan using the Prevent (Inline) protection mode.

  • The policy workflow in Prevent (Inline) protection mode will not apply to the excluded user.

However, these factors might affect this expected behavior:

  1. If the excluded user is a member of a Microsoft 365 group that includes other users protected by a Prevent (Inline) policy.

  2. If the email is sent to other users who are protected by a Prevent (Inline) policy.

Scenarios and Expected Behavior for Excluded Users in Prevent (Inline) Policies:

Email sent only to the excluded user

Email sent to excluded user and another protected user

Email sent to group

Policy protection mode

Workflows applied?

Policy protection mode

Workflows applied?

Policy protection mode

Workflows applied?

Excluded user is part of a protected Microsoft 365 group

Prevent (Inline)

No

Prevent (Inline)

Yes

Prevent (Inline)

Yes

Excluded user is part of another protected group (not Microsoft 365)

Detect

No

Detect

No

Detect

No

Excluded user is not part of any protected group

Detect

No

Detect

No

Detect

No

Example:

Consider a policy in Prevent (Inline) protection mode with these settings:

  1. The policy applies to all users except John Smith.

  2. The policy workflow is configured to quarantine phishing emails.

  3. John Smith is part of a Microsoft 365 group with James Wilson.

Scenario 1: A phishing email is sent only to John Smith (excluded user)

Result: The email was inspected and identified as phishing but delivered to John Smith's mailbox since the Prevent (Inline) policy was not applied, and the email was not quarantined.

Scenario 2: A phishing email is sent to both John Smith (excluded user) and James Wilson (protected user)

Result: The email was inspected, identified as phishing, and quarantined. John Smith's email was not delivered, though he was excluded from the policy.

Scenario 3: A phishing email is sent to John Smith and James Wilson (both part of a protected Microsoft 365 group)

Result: The email was inspected, identified as phishing, and quarantined. Both John Smith and James Wilson do not receive the email.

Scenario 4: A phishing email is sent to John Smith and James Wilson (both John Smith and James Wilson were part of a different group type

Result: The email was inspected and identified as phishing. The email is delivered to John Smith's mailbox without being quarantined.