Where did the Phish delivered due to ETR override default alert go?

IniobongNkanga-8038 966 Reputation points
2024-10-08T16:22:11.7266667+00:00

Hello

Please i need your help on this issue.

I noticed that the Phish delivered due to ETR override default alert go inside Microsoft defender?

How can i create a default Phis delivered due to ETR Override

User's image

Exchange Online
Exchange Online
A Microsoft email and calendaring hosted service.
6,204 questions
Outlook | Windows | Classic Outlook for Windows | For business
Exchange | Other
Community Center | Not monitored
{count} votes

1 answer

Sort by: Most helpful
  1. Mike Hu-MSFT 4,145 Reputation points Microsoft External Staff
    2024-10-09T06:02:48.1733333+00:00

    It looks like you're interested in understanding how to create a default alert for "Phish delivered due to ETR override" in Microsoft Defender. Here's a brief overview of the process:

    1. Understanding ETR Override: Exchange Transport Rules (ETR) are used to apply specific actions to messages as they pass through the transport pipeline. An ETR override can allow a phishing email to be delivered despite other security measures
    2. Creating the Alert:
    • Navigate to Microsoft Defender: Go to the Microsoft 365 Defender portal.
    • Create a New Alert Policy: Under the "Alerts" section, create a new alert policy.
      • Define Conditions: Set the conditions to trigger an alert when a phishing email is delivered due to an ETR override. You can specify the criteria based on the message properties and the actions taken by the ETR.
      Review and Save: After defining the conditions, review the settings and save the alert policy. This will ensure that you receive notifications whenever a phishing email is delivered due to an ETR override

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.