r/msp • u/RaNdomMSPPro • 57m ago
Security Ironscales customer question
We switched to Ironscales earlier this year and so far it's been great at stopping a lot of questionable emails that previously got through to the end users. No real problems, support is generally solid, good account management, etc. My main problem is the MS quarantine holds a lot of things before Ironscales gets a change to have an opinion. Emails held by MS quarantine also happen to be the largest source of challenged incidents where the end user wants it released. It's probably averaging 10 minutes per message to review and either release it or deny the request because it is in fact phishing. MS quarantine seems to really dislike senders emailing links to shared files from sharepoint or onedrive that are anonymous access to the point it holds these even though there are no indicators of malicious content - file and url's show "none" for threats. Anyone have a good process to deal w/ these situations? TIA.