Up Introducing Override Alerts
We’re introducing override alerts for Microsoft Defender for Office 365 Plan 1 and Plan 2. These new system alert policies will enable security admins to receive alerts if a message with a high confidence phish or malware verdict is delivered to a mailbox due to one of the following overrides:
- Phish delivered due to an IP allow policy
- Phish delivered due to an ETR override.
- Phish delivered because a user’s Junk Mail Folder is disabled.
- Phish not zapped because ZAP is disabled.
- Malware not zapped because ZAP is disabled.