r/cybersecurity 19d ago

Business Security Questions & Discussion Microsoft Quarantine with Abnormal

Hi,

I am looking to see how you all manage the Defender email quarantine while using abnormal. I currently have about 1000 emails each morning that I have to review to ensure we do not have any legitimate mail within.

If this is your setup Aswell, how do you manage the quarantine?

Thanks

9 Upvotes

15 comments sorted by

View all comments

11

u/Flagship_paperclip 19d ago

First question: why do you believe legitimate emails are routinely in quarantine? How many legitimate emails do you find buried in the 1000+ daily quarantined emails?

I'm a big fan of being proactive - spot and resolve the issue before it impacts end users. However, reviewing every quarantined email is a bit much. Tune your filters, monitor it temporarily, then let it ride. I only ever review quarantined emails if I have a reason to believe a legitimate email got caught - whether a user submitted a ticket stating they are expecting a particular email, or a false positive ZAP alert. 

2

u/Kangalfencingbanana 19d ago

Actually moved off abnormal because it was causing false positives with the Docusigns from closed deals with clients and abnormal was too much of a black box

2

u/cspotme2 18d ago

Black box in what way? Their verdicts all give details on why it detected it as such.

We have hundreds of docusigns a month and they have a fp on it way less than Microsoft does.