How to block spam emails based on patterns in Exchange Online using Data loss prevention.
To create a spam email block policy based on patterns in Microsoft Exchange Online with DLP 365 you can follow the steps outlined below:
For instance, if you are receiving spam emails from various
accounts, Blow example email Password expiration reminder. Normally we don’t
receiving emails like that.
.
In Exchange online before we create these rules in Exchange
online now it moved to DLP (Data loss prevention) under https://compliance.microsoft.com/datalossprevention
To create policy please follow following steps.
1.
Login to https://compliance.microsoft.com/datalossprevention
2.
go under DLP and Create
Policy
3.
Select: Categories: Custom,
Template Custom policy, Click Next
4.
Provide the name and
description and Click Next
5.
Skip Admin units if you can
see this option.
6.
Choose location to apply
the policy.
a.
Note: you can choose all
location but our policy for incoming emails to we will choose Exchange only.
Click Next
7.
Define Policy Settings
Choose: Create or customize advance DLP rules and Click Next
8.
Customize advanced DLP
rules: Click Create Rule
a.
Provide All required
information.
b.
In conditions select Recipient
domain is (Your Domain) and
c.
In conditions select
Subject matches patterns condition
i.
Put all the patterns from
spam email subject line.
d.
In Conditions you also can choose
Subject or Body matches patterns
Note: you can use condition AND or OR between two policies
if you want both the policies to must apply select AND or if you want
any of the policy to apply select OR
Note:
In our case we creating policy for incoming email that’s why we have recipient
domain and our policy based on subject matches patterns.
e.
Actions: you can select
request action to block in quarantine or forward the message
f.
Click Save
g.
You can also apply settings
to send alerts (Use this severity level in admin alerts and reports:)
9.
Click Next
10Policy mode: you can test before
Turn it on: Click Next
11Review and Click Submit
12To test the effectiveness
of the policy, you can send an email to your M365 email address using the same
patterns. As a result, all such emails will be blocked and sent to quarantine.
You can access the Quarantine section by navigating to
security.microsoft.com > Email & Collaboration > Review >
Quarantine.
Comments
Post a Comment