Exchange - Auto Forwarding Rule Applying Prior to ATP Scanning

Hugh Bowers 26 Reputation points
2022-05-29T23:27:55.767+00:00

My org is using a SaaS app (intercom.io) for customer support

We have an Exchange online mailbox with rule in place to auto forward all mail over to the intercom domain

What we are finding is the message is forwarded prior to any threat scanning taking place, meaning that spam/phishing mail is being sent over before being sent to quarantine by MS365 Defender

I have replicated the flow and tried different ways of forwarding (internal mailbox rule/SMTP forward through EAC/Transport rule) and they are all processed the same way. I've also looked for an answer to what sounds like a simple setup and have come up with nothing (closest thing I've found is here https://learn.microsoft.com/en-us/answers/questions/648337/apply-atpspamphishing-protection-on-forwarded-mess.html)

What I want to know is if this is expected behaviour and should we be relying on inbound protection on the other side

Mail trace excerpt included below

Sender: ******@domain1.com
Recipient: ******@mydomain.com

Received -> Processed -> Delivered

Status: The message was forwarded to the Inbox folder of the following address:<br/><br/><b>Redirected to:</b> ‎******@intercomdomain.com

Date (UTC) | Event | Detail |

5/22/2022, 4:58 PM | Receive | Message received by: XXXX.prod.outlook.com using TLS1.2 with AES256

5/22/2022, 4:58 PM | Redirect | The message was directed to ******@intercomdomain.com.

5/22/2022, 4:58 PM | Defer | Reason: 400 4.7.721 Advanced Threat Protection scanning in progress.

5/22/2022, 5:01 PM | Receive |

5/22/2022, 5:01 PM | Spam | No detail information available.

5/22/2022, 5:01 PM | Spam | No detail information available.

5/22/2022, 5:01 PM | Receive |

5/22/2022, 5:01 PM | Send external |

5/22/2022, 5:01 PM | Send | Message sent to quarantine.

5/22/2022, 4:58 PM | Send external |

Exchange Online
Exchange Online
A Microsoft email and calendaring hosted service.
6,182 questions
0 comments No comments
{count} vote

Accepted answer
  1. Yuki Sun-MSFT 41,376 Reputation points Moderator
    2022-05-30T07:14:31.97+00:00

    Hi @Hugh Bowers

    What I want to know is if this is expected behaviour and should we be relying on inbound protection on the other side

    As far as I know, yes, as indicated in the message trace logs you shared above, it's expected that the auto forwarding rule would be processed before ATP. So for the situation you described, agree that inbound protection needs to be configured to the other side as well.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    2 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.