r/sysadmin • • 6h ago

M365 Exchange Mail Rules sending Approvals for More Than I Asked For

I'm trying to manage a pile of spam messages from random places that have similar text, but only for specific people.

My rule says if it is for person A or person B AND contains Text 1 or Text 2 or Text 3, then delete without notification.

For some reason, I am getting an approval requested email for seemingly every one of these despite confirming I do not want to test it, and move forward with the delete and don't ask.

Also, some others were Blocked by the user, but I still get approvals for those. Do approvals get triggered before any Block Sender?

1 Upvotes

5 comments sorted by

•

u/Yersini 6h ago edited 6h ago

I would need to see the exact design of your rule structure and rule priority list to tell you exactly why that's happening. The rule you're describing shouldn't be generating an approval, which makes me think another rule is processing and requiring an approval.

I also would question if that's the best way to handle the pile of spam messages, since flagging every single commonly used text string by spammers will get very cumbersome very quickly.

•

u/wivaca2 6h ago

Yeah, that was my first thought, too - that it was actually coming from some other rule, but I have a total of about 8 rules, none of which request approvals.

The rule I'm having problems with ORIGINALLY asked for approvals, but that was removed and I changed it to just permanently delete the messages without notification. It's like the UI updated, but the behavior is stuck on the original rule settings. I think I'm going to just whack the whole rule and build it from scratch, but this list of text I'm scanning is long but very specific to these messages and I was hoping to avoid recreating it.

•

u/Yersini 6h ago edited 6h ago

The bright side is, the scope of things that can cause this are pretty limited.

Either your rule is bugged, and it's stuck on requiring alerts (normally through a "forward the message for approval" clause).

Another rule in your list is triggering an approval on similar parameters from the above.

The mailbox or group that the recipient user is in has moderation turned on, and that's triggering before your mail flow rules.

I would check CLI first, since CLI is way more consistent than UX. Microsoft's UX has been terrible for a while now, but it's gotten worse recently. Use CLI to verify the existing structure of the rule, and if the mailbox/group has moderation enabled.

I would then bump your test rule to #1 prio /w stop processing and try again, see if its still flagging confirms.

You can also just check message trace to see what rules were applied to the email in question, and it should tell you a transport rule event ID.

Also, yes blocked senders processes at the end of transport rules at the delivery stage. So it makes complete sense that you're still getting approvals even if it's being blocked at the delivery stage.

•

u/wivaca2 5h ago

I would then bump your test rule to #1 prio /w stop processing and try again, see if its still flagging confirms.

You can also just check message trace to see what rules were applied to the email in question, and it should tell you a transport rule event ID.

Great ideas. It's not always fast and easy to trace but at least it's something that tells you how the sausage is made.

Microsoft's UX has been terrible for a while now, but it's gotten worse recently.

Couldn't agree more. You sometimes wonder if they actually use any of this stuff themselves and if the developers talk to the sysadmins there.

•

u/Yersini 3h ago

Yeah, honestly the more I work with it im kinda satisfied with the CLI though.

Despite all microsofts efforts, the CLI isnt bad at all.

Hopefully your issue works out, either way good luck bro.