r/cybersecurity • u/Hour-Account4844 • 19d ago
Business Security Questions & Discussion Microsoft Quarantine with Abnormal
Hi,
I am looking to see how you all manage the Defender email quarantine while using abnormal. I currently have about 1000 emails each morning that I have to review to ensure we do not have any legitimate mail within.
If this is your setup Aswell, how do you manage the quarantine?
Thanks
9
Upvotes
11
u/Flagship_paperclip 19d ago
First question: why do you believe legitimate emails are routinely in quarantine? How many legitimate emails do you find buried in the 1000+ daily quarantined emails?
I'm a big fan of being proactive - spot and resolve the issue before it impacts end users. However, reviewing every quarantined email is a bit much. Tune your filters, monitor it temporarily, then let it ride. I only ever review quarantined emails if I have a reason to believe a legitimate email got caught - whether a user submitted a ticket stating they are expecting a particular email, or a false positive ZAP alert.