Tenant Allow/Block Lists

Marc 631 Reputation points
2022-01-05T16:30:58.987+00:00

In Microsoft 365 Defender we have:

Allowed and blocked senders and domains

Connection filtering (IP Allow list - IP Block list)

It is not clear for me what exactly does "Tenant Allow/Block Lists" (senders, spoofing, URLs, Files).

Exchange | Exchange Server | Management
Exchange | Exchange Server | Management
The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.
{count} votes

7 answers

Sort by: Most helpful
  1. Andy David - MVP 159.7K Reputation points MVP Volunteer Moderator
    2022-01-05T17:07:52.167+00:00

  2. KyleXu-MSFT 26,396 Reputation points
    2022-01-06T08:04:30.873+00:00

    @Marc

    The Allow/Block list could override the Microsoft 365 filtering verdicts.

    Such as you add a mailbox to the allow list, this mailbox will bypass the filter of spam even though this mailbox sends spam. If you add this mailbox to the block list, emails sent from this mailbox will be blocked.

    About the spoofing session, here is an example:

    I don't want emails from "contoso.net" blocked by Office 365, so, I add it into the allow list. (In this way, all emails from that domain could be delivered to my tenant)
    162821-qa-kyle-15-51-34.png

    But now, I don't want to receive emails from that domain, I would edit this rule from allow to block. (In this way, non-junk emails also cannot be delivered)

    If I remove this rule, all emails sent from "contoso.net" will be judged by Microsoft 365 filtering. (Junk email will be blocked, no-junk email could be delivered)

    About the creating of filter rule, you could have a look about this part.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


    0 comments No comments

  3. Marc 631 Reputation points
    2022-01-12T21:32:06.397+00:00

    If a message is considered high confidence phish/spoof or when we have the Spoof intelligence enabled then it takes precedence over other policies. In this case is it useless add the email to the Tenant Allow Lists, isn't it? Will allow list unlock the restrictive office 365 policies ?

    What are the services that can be blocked by Office 365 and could be overwritten by "Tenant Allow / Block Lists"?


  4. Marc 631 Reputation points
    2022-01-20T16:48:04.61+00:00

    I need help to understand another thing.
    In Senders we have "remove on".
    What does this removal refer to? What is going to happen on 21-Jan-22?
    Will it be deleted from the submission/quarantine list?
    Thanks

    166855-tenant-allow-2.png

    0 comments No comments

  5. Andy David - MVP 159.7K Reputation points MVP Volunteer Moderator
    2022-01-20T18:41:01.55+00:00
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.