nerdexam
Microsoft

MS-102 · Question #316

You have a Microsoft 365 E5 subscription. You plan to use a third-party protection service to scan email messages before they are delivered to Microsoft 365. You configure a mail flow rule to bypass…

The correct answer is A. a message that contains malware B. a high-confidence phishing message. In Microsoft 365, two categories of threats cannot be bypassed by mail flow rules under any circumstances: (A) Messages containing malware - the malware filter always runs regardless of any bypass rules. This is a hard-coded protection that cannot be overridden. (B)…

Submitted by andres_qro· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 E5 subscription. You plan to use a third-party protection service to scan email messages before they are delivered to Microsoft 365. You configure a mail flow rule to bypass spam filtering for incoming messages. Which two messages will still be scanned by Microsoft 365 and cannot be bypassed by the mail flow rule? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • Aa message that contains malware
  • Ba high-confidence phishing message
  • Can encrypted message
  • Da message that includes HTML code
  • Ea messages that includes URL links

How the community answered

(37 responses)
  • A
    78% (29)
  • C
    14% (5)
  • D
    5% (2)
  • E
    3% (1)

Explanation

In Microsoft 365, two categories of threats cannot be bypassed by mail flow rules under any circumstances: (A) Messages containing malware - the malware filter always runs regardless of any bypass rules. This is a hard-coded protection that cannot be overridden. (B) High-confidence phishing messages - Microsoft treats these as a critical threat class and enforces filtering even when bypass rules are present. In contrast, regular spam, HTML content, URL links, and encrypted messages can potentially be affected by bypass rules because they are not classified as absolute security overrides. This design ensures that the most dangerous threat types are never skipped by administrative misconfiguration.

Topics

#Mail flow rules#Email security#Microsoft Defender for Office 365#Threat protection bypass

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice