Share via

How to restrict specific email addresses, that are in our domain but not in an allowed group from journaling

Andrew Bonser 0 Reputation points
2026-03-10T20:58:14.76+00:00

How to restrict specific email addresses, that are in our domain, but not in an allowed Journal rules group from journaling?

Exchange Online
Exchange Online

A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.

0 comments No comments

2 answers

Sort by: Most helpful
  1. TiNo-T 12,015 Reputation points Microsoft External Staff Moderator
    2026-03-10T23:20:54.5733333+00:00

    Dear @Andrew Bonser,

    Welcome to Microsoft Q&A Forum!

    Thank you for your patience, and I completely understand how confusing and frustrating this situation can be, especially when you expect journaling to apply only to a specific set of users.

    After reviewing your scenario, I’d like to clarify what is happening and why this behavior is expected in Exchange Online, along with some suggestions that you may consider.

    1.What is happening:

    In Exchange Online, journaling rules are evaluated at the organization level, not on a strict “allowed users only” basis. When a journaling rule is scoped to a distribution group or mail‑enabled security group, Exchange journals any message where at least one participant (sender or recipient) is a member of that group. As a result, if a journaled user sends or receives an email with another internal user who is not in the allowed group, the message may still be journaled. Unfortunately, Exchange Online journaling may not support exclusion logic, such as:

    • Excluding specific internal users
    • Using deny lists
    • Applying exceptions or conditional rules

    This is an expected behavior, not a misconfiguration.

    2.Why this cannot be restricted further:

    Journaling in Exchange is designed for compliance capture, not granular filtering. For this reason, it may not support:

    • “Journal only if both sender and recipient are in the group”
    • Excluding specific mailboxes once a journaling rule applies

    Therefore, here are several ideas that you may consider:

    Depending on your business or compliance requirements, you may want to consider one of the following:

    1.Use a tightly controlled journaling group:

    Ensure only the exact mailboxes that must be journaled are members of the group (no shared mailboxes or service accounts).

    2.Use mail flow (transport) rules for conditional processing:

    Transport rules support conditions and exceptions based on sender/recipient and group membership.

    Please note that transport rules are not a full replacement for journaling in regulated compliance scenarios.

    3.Consider a third‑party archiving or compliance solution:

    These solutions typically support more advanced inclusion/exclusion logic when strict scoping is required.

    Note: This third suggestion is provided as a convenience to you. This idea is not controlled by Microsoft, and Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found in third-party documents. Please ensure that you fully understand the risks before using any suggestions from third-party links. I cannot provide or support further about it, please kindly research and take responsibility on your own.

    Also, you may find the following Microsoft documentations helpful for further confirmation:

    In these documents, you may see that journaling rules apply when either the sender or recipient matches the rule scope and that exclusions may not be supported.

    Besides that, you can take a look in the answer of Q&A Assists AI to see if they can give you some insights.

    I truly understand the inconvenience may cause, and I hope this explanation helps clarify why the behavior occurs and what options are available.


    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Q&A Assist
    2026-03-10T20:58:25.43+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Use targeted journal rules so that only members of the “allowed” group are journaled and everyone else in the domain is excluded.

    In Exchange Online journaling, the behavior is:

    • The journal recipient is the SMTP address (mailbox, distribution group, dynamic distribution group, mail user, or contact) whose traffic is journaled.
    • All messages sent to or from the journaling recipients specified in a rule are journaled.
    • If no journal recipient is specified on a rule, then all recipients that match the rule’s scope (Internal / External / All) are journaled.

    To restrict journaling to only an allowed group and exclude other internal addresses:

    1. Create (or use) a distribution group that contains only the internal users that must be journaled.
    2. Create a journal rule that:
      • Sets Journal recipient to that distribution group.
      • Sets Journal rule scope as needed (for example, Internal messages only, External messages only, or All messages).
      • Sets Journaling mailbox to the appropriate external journaling mailbox/archiving system.
    3. Ensure there is no other journal rule without a Recipient (journal recipient) defined and no other rule that targets “all messages” for the entire organization, because:
      • A rule without a journal recipient journals all recipients that match the scope.
      • That would override the attempt to restrict journaling to only the allowed group.

    With this configuration, only messages sent to or from members of the allowed group are journaled; other internal addresses in the same domain are not journaled because they are not specified as journal recipients in any rule.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.