Transport Rules are sending multiple/duplicate moderation emails for approval

Rob Banks 41 Reputation points
2022-11-24T02:22:42.567+00:00

We have a hybrid on premise and 365 cloud configuration consisting of Exchange 2013 CU23 and Exchange 2016 for some shared and system mailboxes that cannot be migrated to 365 and the rest of our user mailboxes (several thousand) are migrated to the cloud. Since 2019, we have been having recurring and intermittent problems on the 2013 DAG where users in one of the teams at our company send external emails out which require moderation approval and once approved, a duplicate or multiple approval requests are sent again by Exchange, even after being approved.

We have worked on it extensively with Microsoft Support and they have never been able to solve this, and eventually the problem ceases but eventually recurs months later. Since we migrated all of our user mailboxes to the cloud last year, this problem has returned and gotten extensively worse. Multiple email moderation requests for approval are being sent, sometimes 3-5 times for each outbound email. The affected team of moderators has grown increasingly impatient and Microsoft support has shown little interest in getting this fixed and is not devoting much attention here.

I'm willing to provide as much detail as possible here, but below is a common scenario:

  • End user sends email to external recipient with one of several qualifying attachments (doc, docx, xlsx, pdf, txt, etc)
  • If the email contains an attachment such as any of the above extensions and is being sent externally, the rule is invoked and a moderation request is
    sent to a specified moderator in the rule for approval.
  • Moderator approves the request and email is sent
  • Several more moderation requests for approval to send the same email are sent to the moderator; the email has already been sent externally so this does not serve any purpose
  • Often times, these outbound emails are being sent on behalf of a shared mailbox that resides on premise by a user mailbox which resides in the cloud.
  • The shared mailboxes reside in a Exchange 2013 DAG with CU23
  • The user mailboxes are linked mailboxes and were migrated from the Exchange 2013 DAG to M365
  • The Exchange 2016 DAG is part of a separate domain that has a trust relationship with the domain that the 2013 Exchange DAG belongs to; all email sent from on premise is routed from Exchange 2013 through Exchange 2016 to the internet.
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,357 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,896 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Amit Singh 4,846 Reputation points
    2022-11-24T10:42:42.863+00:00

    Here are a few steps to troubleshoot the issue:

    Ensure arbitration mailboxes are moved to Exchange 2016.
    Delete and recreate rules.
    Move the moderator's mailbox to Exchange 2016.
    Restart transport services.

    Multiple Moderation Approval Requests: http://byronwright.blogspot.in/2017/06/multiple-moderation-approval-requests.html

    Get the complete details about Client Connectivity in an Exchange: https://blogs.technet.microsoft.com/exchange/2015/10/26/client-connectivity-in-an-exchange-2016-coexistence-environment-with-exchange-2010/


  2. Rob Banks 41 Reputation points
    2022-11-29T07:22:50.603+00:00

    I've done extensive investigation and research tonight and may have found the issue. When a user sends an email to an external recipient with a qualifying attachment (pdf, docx, etc), the message is submitted to moderators automatically by the transport rules for approval

    1. The system attendant/arbitration mailbox sends the approval request to a moderator for approval, and the message is approved and released for delivery
    2. I noticed when this happens, the message is dropped or blocked and no information is provided in the Explorer portal at security.microsoft.com why
    3. The moderator receives a duplicate approval request immediately after, approves it and the message is released for delivery and the final status is delivered, or the Latest delivery location shows: On-prem/external

    I'm unable to find any reason anywhere why these messages are being dropped/blocked, and its only happening when the duplicate moderation requests arrive. I kept asking myself, "Why isnt anyone noticing that the recipients are receiving their emails, and I noticed right after the dropped or blocked status, the same message shows again as delivered.

    I cant find anything online about this, does this mean anything to you? We had a heated meeting with our support engineer covering the case today; they simply are not able to come up with anything here and the only reason we are this far is because I'm doing all of the work.