Reference
Exchange Security Policy
Microsoft Defender for Office 365 / EOP security policies — anti-phish, anti-spam, Safe Links, Safe Attachments, malware filter, outbound spam, and quarantine policies.
Part of the Exchange inventory.
Scan settings
| Default scanning interval | Allowed scanning intervals | Data removal during incremental scan |
|---|---|---|
| Weekly | Daily, Weekly, Bi-Weekly, Monthly, Never, Initial | Yes |
Properties
| Property | Type | Description | Automation placeholder |
|---|---|---|---|
| Action | String | Primary action of the policy (e.g. Block, Replace, Quarantine, Redirect). | {{ExchangeSecurityPolicy.Action}} |
| Allow Click Through | Boolean | Whether users can click-through Safe Links warnings. | {{ExchangeSecurityPolicy.AllowClickThrough}} |
| Allowed Sender Domains | String[] | Domains allow-listed by this anti-spam policy. Highest-risk anti-spam misconfig per Microsoft guidance. | {{ExchangeSecurityPolicy.AllowedSenderDomains}} |
| Allowed Senders | String[] | {{ExchangeSecurityPolicy.AllowedSenders}} | |
| Bulk Threshold | Int32 | {{ExchangeSecurityPolicy.BulkThreshold}} | |
| Initially Scanned | DateTime | Shows when this object was initially found in a scan. | {{ExchangeSecurityPolicy.CreatedTime}} |
| Policy Name | String | {{ExchangeSecurityPolicy.DisplayName}} | |
| Do Not Rewrite URLs | String[] | {{ExchangeSecurityPolicy.DoNotRewriteUrls}} | |
| Drift From Standard Baseline | Boolean | True when the policy deviates from Microsoft's recommended Standard preset. | {{ExchangeSecurityPolicy.DriftFromStandard}} |
| Drift From Strict Baseline | Boolean | True when the policy deviates from Microsoft's recommended Strict preset. | {{ExchangeSecurityPolicy.DriftFromStrict}} |
| Enable File Filter | Boolean | {{ExchangeSecurityPolicy.EnableFileFilter}} | |
| Enable Mailbox Intelligence | Boolean | {{ExchangeSecurityPolicy.EnableMailboxIntelligence}} | |
| Enable Safe Links For Email | Boolean | {{ExchangeSecurityPolicy.EnableSafeLinksForEmail}} | |
| Enable Safe Links For Office | Boolean | {{ExchangeSecurityPolicy.EnableSafeLinksForOffice}} | |
| Enable Safe Links For Teams | Boolean | {{ExchangeSecurityPolicy.EnableSafeLinksForTeams}} | |
| Enable Safe List | Boolean | {{ExchangeSecurityPolicy.EnableSafeList}} | |
| Enable Spoof Intelligence | Boolean | {{ExchangeSecurityPolicy.EnableSpoofIntelligence}} | |
| Enable Targeted User Protection | Boolean | {{ExchangeSecurityPolicy.EnableTargetedUserProtection}} | |
| Enabled | Boolean | {{ExchangeSecurityPolicy.Enabled}} | |
| End User Quarantine Permissions | String | {{ExchangeSecurityPolicy.EndUserQuarantinePermissions}} | |
| File Types | String[] | {{ExchangeSecurityPolicy.FileTypes}} | |
| High Confidence Phish Action | String | {{ExchangeSecurityPolicy.HighConfidencePhishAction}} | |
| High Confidence Spam Action | String | {{ExchangeSecurityPolicy.HighConfidenceSpamAction}} | |
| IP Allow List | String[] | {{ExchangeSecurityPolicy.IPAllowList}} | |
| IP Block List | String[] | {{ExchangeSecurityPolicy.IPBlockList}} | |
| Impersonation Protection State | String | {{ExchangeSecurityPolicy.ImpersonationProtectionState}} | |
| Is Default | Boolean | {{ExchangeSecurityPolicy.IsDefault}} | |
| Last scan update | DateTime | Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. | {{ExchangeSecurityPolicy.LastModifiedTime}} |
| Phish Spam Action | String | {{ExchangeSecurityPolicy.PhishSpamAction}} | |
| Phish Threshold Level | Int32 | 1 (Standard) to 4 (Most aggressive). | {{ExchangeSecurityPolicy.PhishThresholdLevel}} |
| Policy Id | String | {{ExchangeSecurityPolicy.PolicyId}} | |
| Policy Type | String | Allowed values: AntiPhish, AntiSpam, ConnectionFilter, Malware, OutboundSpam, Quarantine, SafeAttachment, SafeLinks. | {{ExchangeSecurityPolicy.PolicyType}} |
| Quarantine Retention Days | Int32 | {{ExchangeSecurityPolicy.QuarantineRetentionDays}} | |
| Redirect Address | String | {{ExchangeSecurityPolicy.RedirectAddress}} | |
| Risk Score | Int32 | Stores risk score | {{ExchangeSecurityPolicy.RiskScore}} |
| Risk Score Update | DateTime | Stores risk score update | {{ExchangeSecurityPolicy.RiskScoreLastUpdate}} |
| Risk Score Value | String | Stores risk score value like Low_Low | {{ExchangeSecurityPolicy.RiskScoreValue}} |
| Safe Attachment Action | String | Allowed values: Allow, Block, DynamicDelivery, Replace. | {{ExchangeSecurityPolicy.SafeAttachmentAction}} |
| Spam Action | String | {{ExchangeSecurityPolicy.SpamAction}} | |
| Targeted Users To Protect | String[] | {{ExchangeSecurityPolicy.TargetedUsersToProtect}} | |
| Track Clicks | Boolean | {{ExchangeSecurityPolicy.TrackClicks}} | |
| ZAP Enabled | Boolean | Zero-hour Auto Purge enabled. | {{ExchangeSecurityPolicy.ZapEnabled}} |
Relations
This object does currently not have any relations.
Segments
| Segment | Description |
|---|---|
| Disabled security policies | Defender and EOP security policies that are currently disabled. |
| Policies drifting from Standard | Defender and EOP policies that deviate from Microsoft's Standard protection baseline. |
Actions
This object does currently not have any actions.
Policies that check this object
| Policy | Severity | Description |
|---|---|---|
| Defender policy drifts from Standard baseline | Medium | Detects Defender / EOP security policies that deviate from Microsoft's recommended Standard preset. |
| Safe Links policy allows click-through | Medium | Detects Safe Links policies where users can click through warnings on phishing URLs. |