Configuring Malware Policy for Microsoft Teams

Malware Policy

By default, the Microsoft Teams malware policy scans for malicious content in the files sent using Microsoft Teams.

Supported Actions

Microsoft Teams malware policy supports these actions:

  • Tombstone of files and text messages that contain malicious content.

    • If malicious content is found, the sender will get the tombstoned message.

      For information about unblocking the tombstoned message, see Unblocking Messages.

    • If malicious content is found, the recipient(s) will get the tombstoned message.

  • Alert sender: Sends an email notification to the sender of a file or message that contains malicious content.

  • Alert admin(s): Sends an email notification to the admin(s) about the malicious files or messages.

Configuring Malware Policy

  1. Click Policy on the left panel of the Email Security Administrator Portal.
  2. Click Add a New Policy Rule.
  3. From the Choose SaaS drop-down list, select Microsoft Teams.
  4. From the Choose Security drop-down list, select Malware and click Next.
  5. Select the desired protection mode (Detect and Remediate or Detect).

    If required, you can change the Rule Name.

  6. Under Blades, select the threat detection blades required for the policy.
    Note:

    To select all the blades available for malware detection, enable All running threat detection blades checkbox.

  7. Configure Actions required from the policy.
    • To tombstone messages, enable the Tombstone Message checkbox.

      Note:

      This option will be available only in Detect and Remediate protection mode and when URL Reputation threat detection blade is enabled.

    • To tombstone files, enable the Tombstone File checkbox.

      Note:

      This option will be available only in Detect and Remediate protection mode and when the Anti-Malware threat detection blade is enabled.

    • To send email alerts to the sender about malware in messages and files, enable the Alert sender - messages and Alert sender - files checkbox.

    • To send email alerts to admins about malware in messages and files, enable the Alert admin(s) - messages and Alert admin(s) - files checkbox.

    Note:
    • Even when the alerts are enabled here in the policy, the administrator only receives email alerts for security events when Receive Alerts role is enabled in the Specific Service Role. For more details about managing roles and permissions in the Check Point Portal, refer to Global Settings > Users in Check Point Portal Administration Guide.

    • To customize the email alert templates, click on the gear icon to the right of the alert.

  8. Click Save and Apply.