-> Enhanced Filtering for Connectors doesn't work for third-party phishing simulations in email routing scenarios which involve emails coming to Exchange online twice (for example, email from the internet is routed to Microsoft 365, then to an on-premises environment or third-party security service, and then back to Microsoft 365). EOP can't identify the true IP address of the message source. Don't try to work around this limitation by adding the IP addresses of the on-premises or third-party sending infrastructure to the third-party phishing simulation. Doing so effectively bypasses spam filtering for any internet sender who impersonates the domain that's specified in the third-party phishing simulation. Note that email routing scenario where MX points to 3rd party and then routed to exchange online is still supported if enhanced filtering for connectors is setup.
0 commit comments