Threat Detection Policy for Outgoing Emails

Administrators can enable threat detection to prevent malware, phishing, and spam emails from being sent by their organization's users to external parties.

Note:

This feature is supported only for Office 365 Mail.

Configuring a Threat Detection Policy Rule for Outgoing Emails

  1. Navigate to Policy on the left panel of the portal.
  2. Click on an Office 365 Mail Threat Detection policy rule.

    If you do not have a Office 365 Mail Threat Detection policy rule, create a new policy. See Threat Detection Policy for Incoming Emails.

  3. Select the desired policy protection mode (Detect, Detect and Remediate or Prevent (Inline)).

    If required, you can change the Rule Name.

  4. Under Scope, select the users and groups to which the policy is applicable and click Add to Selected.
    • To apply the policy to all users and groups in your organization, select All Users and Groups checkbox.

    • To apply the policy only to specific users or groups, select the users/groups and click Add to Selected.

    • To exclude some of the users or groups from the policy, select the users/groups and click Add to Excluded.

    For more information about excluded users, see Excluding Members of Microsoft 365 Groups from a Prevent (Inline) Policy.

  5. Select the workflows required for the policy.
    Note:

    If you select Detect and Remediate or Detect mode, you may not see some of these additional configuration options that allows you to customize the end user email notifications.

    For more information on workflows, see Phishing Protection, Malware Protection, and Password Protected Attachments Protection.

  6. Scroll down and expand Advanced Configuration.
  7. Under Advanced Settings, enable Protect (Inline) Outgoing Traffic checkbox.
  8. Click Save and Apply.