Deliver emails to the user managed quarantine and administrative quarantine
In this tutorial, you will learn to deliver SPAM
and SPOOF
messages to the user managed quarantine, and MALICIOUS
messages to the administrative quarantine (this requires an administrator to release the emails).
Configure domains
You first need to configure the domains you are onboarding on the Area 1 dashboard. To configure your domains:
- Log in to the Area 1 dashboard.
- Go to Settings (the gear icon).
- Go to Email configuration > Domains & Routing > Domains.
- Make sure each domain you are onboarding has been added.
- For each domain you are configuring, select … > Edit, and set the following options:
- Domain -
<YOUR_DOMAIN>
. - Configured as -
MX Records
. - Forwarding to - This should match the expected MX record for each domain in your Office 365 account.
- IP Restrictions - Leave this field empty.
- Outbound TLS -
Forward all messages over TLS
. - Quarantine Policy - Do not check any dispositions.
- Domain -
Create quarantine policies
To create quarantine policies:
-
Open the Microsoft 365 Defender console.
-
Go to Email & collaboration > Policies & rules.
-
Select Threat policies.
-
Under Rules, select Quarantine policies.
-
Select Add custom policy.
-
Set the Policy name to
UserNotifyUserRelease
. -
Select Next.
-
In Recipient message access, select Set specific access (Advanced), and then:
- In Select release action preference, choose Allow recipients to release a message from quarantine.
- In Select additional actions recipients can take on quarantined messages, select the Delete and Preview checkboxes.
-
Select Next.
-
In Quarantine notification, select Enable.
-
Select Next.
-
Review your settings and select Submit.
-
Select Done.
-
Select Add custom policy.
-
Set the Policy name to
UserNotifyAdminRelease
. -
Select Next.
-
In Recipient message access, select Set specific access (Advanced), and then:
- In Select release action preference, from the drop-down menu, choose Allow recipients to request a message to be released from quarantine.
- In Select additional actions recipients can take on quarantined messages, select the Delete and Preview checkboxes.
-
Select Next.
-
In Quarantine notification, select Enable.
-
Select Next.
-
Review your settings and select Submit.
-
Select Done.
Configure quarantine notifications
To configure quarantine notifications:
-
Open the Microsoft 365 Defender console.
-
Go to Email & collaboration > Policies & rules.
-
Select Threat policies.
-
Under Rules, select Quarantine policies.
-
Select Global settings.
-
Scroll to the bottom and set the desired frequency in Send end-user spam notifications every (days). This value can only be incremented in days.
-
Select Save.
Configure anti-spam policies
To configure anti-spam policies:
-
Open the Microsoft 365 Defender console
-
Go to Email & collaboration > Policies & rules.
-
Select Threat policies.
-
Under Policies, select Anti-spam.
-
Select the Anti-spam inbound policy (Default) text (not the checkbox).
-
In the Actions section, scroll down and select Edit actions.
-
Set the following conditions and actions (you might need to scroll up or down to find them):
- Spam: Quarantine message.
- Select quarantine policy: UserNotifyUserRelease.
- High confidence spam: Quarantine message.
- Select quarantine policy: UserNotifyAdminRelease.
- Phishing: Quarantine message.
- Select quarantine policy: UserNotifyAdminRelease.
- High confidence phishing: Quarantine message.
- Select quarantine policy: UserNotifyAdminRelease.
- Retain spam in quarantine for this many days: Default is 15 days. Cloudflare Area 1 recommends 15-30 days.
- Spam: Quarantine message.
-
Select Save.
Create transport rules
To create the transport rules that will send emails with certain dispositions to Area 1:
-
Open the new Exchange admin center.
-
Go to Mail flow > Rules.
-
Select Add a Rule > Create a new rule.
-
Set the following rule conditions:
- Name:
Area 1 User Quarantine Message
. - Apply this rule if: The message headers > includes any of these words.
- Enter text:
X-Area1Security-Disposition
> Save. - Enter words:
UCE
,SPOOF
> Add > Save.
- Enter text:
- Apply this rule if: Select + to add a second condition.
- And: The sender > IP address is in any of these ranges or exactly matches > enter the egress IPs in the Egress IPs page.
- Do the following - Modify the message properties > Set the Spam Confidence Level (SCL) > 5.
- Name:
-
Select Next.
-
You can use the default values on this screen. Select Next.
-
Review your settings and select Finish > Done.
-
Select the rule
Area 1 User Quarantine Message
you have just created, and Enable. -
Select Add a Rule > Create a new rule.
-
Set the following rule conditions:
- Name:
Area 1 User Quarantine Message Admin Release
. - Apply this rule if: The message headers > includes any of these words.
- Enter text:
X-Area1Security-Disposition
> Save. - Enter words:
MALICIOUS
> Add > Save.
- Enter text:
- Apply this rule if: Select + to add a second condition.
- And: The sender > IP address is in any of these ranges or exactly matches > enter the egress IPs in the Egress IPs page.
- Do the following: Modify the message properties > Set the Spam Confidence Level (SCL) > 9.
- Name:
-
Select Next.
-
You can use the default values on this screen. Select Next.
-
Review your settings and select Finish > Done.
-
Select the rule
Area 1 User Quarantine Message Admin Release
you have just created, and select Enable.