Microsoft Defender for Office 365: Four override alerts retire in August 2024
Microsoft Defender for Office 365 is retiring four legacy override alerts that are now mostly redundant due to Secure by default. With Secure by default, ZAP (zero-hour auto purge) blocks high confidence phishing emails by default despite the legacy overrides. The four alerts are:
- Phish not zapped because ZAP is disabled
- Malware not zapped because ZAP is disabled
- Phish delivered due to ETR override
- Phish delivered due to IP allow
As part of the deprecation and rollout,
- These policies will no longer be part of the Alert policies in the Microsoft Defender portal.
- Existing alerts that are already generated will be in the system (part of Alerts) until data retention applies.
- Any features like AIR built on these policies will not function (return no data) but will not result in any crashes or issues to the system.
- Any features like Investigations or post-breach functionalities will not have these alerts as part of the selection, filtering, or processing.
When is the change?
Microsoft plan to turn off these alerts starting August 18, 2024 and ending August 30, 2024.
Who is impacted?
- Phish not zapped because ZAP is disabled: E5/G5 or Microsoft Defender for Office 365 P2 add-on subscription
- Malware not zapped because ZAP is disabled: E5/G5 or Defender for Office 365 P2 add-on subscription
- Phish delivered due to ETR override: E1/F1/G1, E3/F3/G3, or E5/G5
- Phish delivered due to IP allow: E1/F1/G1, E3/F3/G3, or E5/G5
What should I do if I am impacted?
This change will happen automatically by the specified date. No admin action is required. Since these alerts are mostly redundant, Microsoft do not expect any impact.
No Comments