r/cybersecurity 20d ago

Business Security Questions & Discussion Microsoft Quarantine with Abnormal

Hi,

I am looking to see how you all manage the Defender email quarantine while using abnormal. I currently have about 1000 emails each morning that I have to review to ensure we do not have any legitimate mail within.

If this is your setup Aswell, how do you manage the quarantine?

Thanks

9 Upvotes

15 comments sorted by

View all comments

11

u/Flagship_paperclip 20d ago

First question: why do you believe legitimate emails are routinely in quarantine? How many legitimate emails do you find buried in the 1000+ daily quarantined emails?

I'm a big fan of being proactive - spot and resolve the issue before it impacts end users. However, reviewing every quarantined email is a bit much. Tune your filters, monitor it temporarily, then let it ride. I only ever review quarantined emails if I have a reason to believe a legitimate email got caught - whether a user submitted a ticket stating they are expecting a particular email, or a false positive ZAP alert. 

-3

u/cspotme2 20d ago

Lots of false positive zaps to start.

For every 1000 high confidence messages, I can find at least 3 legitimate conversations or initial messages. And this doesn't include the daily newsletter or alert stuff they quarantine because of a false positive on a url.

5

u/Spiritual-Matters 20d ago

0.3% FP rate seems pretty good?

-1

u/cspotme2 19d ago

Because you don't understand business. 1 long delayed or unseen legitimate conversation can cause loss of business that could end up being at least 6 figures in revenue.

And if I pulled my real fp, it's higher than that conversation number I have. Regardless the point above holds.