MS-102 · Question #301
You have a Microsoft 365 E5 subscription that contains a domain named contoso.com. You deploy a new Microsoft Defender for Office 365 anti-phishing policy named Policy1 that has user impersonation…
The correct answer is D. Select Enable mailbox intelligence. To prevent impersonation protection from blocking legitimate emails from trusted external contacts with similar names, enable Mailbox Intelligence.
Question
You have a Microsoft 365 E5 subscription that contains a domain named contoso.com. You deploy a new Microsoft Defender for Office 365 anti-phishing policy named Policy1 that has user impersonation protection enabled for a user named [email protected]. You discover that Policy1 blocks email messages from a regular contact named [email protected]. You need to ensure that the messages are delivered successfully. What should you do for Policy1?
Options
- ASelect Enable domains to protect.
- BConfigure the Phishing email threshold setting.
- CConfigure which users to protect.
- DSelect Enable mailbox intelligence.
How the community answered
(22 responses)- A14% (3)
- B5% (1)
- C5% (1)
- D77% (17)
Why each option
To prevent impersonation protection from blocking legitimate emails from trusted external contacts with similar names, enable Mailbox Intelligence.
'Enable domains to protect' is for protecting specific domains from being impersonated, not for allowing a legitimate external sender who happens to have a similar name to a protected user.
Configuring the 'Phishing email threshold' setting adjusts the aggressiveness of phishing detection but does not specifically address the issue of legitimate external senders being mistakenly identified as impersonators of an internal user.
'Configure which users to protect' is about specifying which internal users are targeted for impersonation protection, not about allowing external senders with similar names.
Enabling Mailbox Intelligence in an anti-phishing policy helps to distinguish legitimate senders from impersonators by understanding the user's communication patterns and frequent contacts. This allows the system to recognize '[email protected]' as a trusted contact, preventing false positives for impersonation against '[email protected]'.
Concept tested: Anti-phishing policy configuration and Mailbox Intelligence
Source: https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/anti-phishing-policies-mdo-configure?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.