<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft false positives outage in Email and Collaboration</title>
    <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224709#M595</link>
    <description>&lt;P&gt;Im happy to hear that Chris, as I heard customers asking about it...quarantine feature for high confidence.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2024 02:42:22 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-08-28T02:42:22Z</dc:date>
    <item>
      <title>Microsoft false positives outage</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224591#M589</link>
      <description>&lt;P&gt;(I opened a ticket with support for the below issue, but as this forum is collecting cobwebs I thought it wouldn't hurt to share)&lt;/P&gt;&lt;P&gt;Today we have had to manage 10x as many restore requests from our users than normal, undoubtedly due to Microsoft outage EX873252 ("Some users' email messages containing images may have been incorrectly flagged as malware and quarantined"). We expect to be getting quite a few more of these during the day as people are waking up.&lt;/P&gt;&lt;P&gt;Questions are:&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;P&gt;Were HEC able to pull any of these misclassified emails from quarantine, or is that impossible for those Microsoft detect as malware?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Microsoft states in their advisory that they have “automatically replayed” 99% of the affected emails. What would be the expected result of that for us running HEC? Would they automatically be released from quarantine?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there any proactive steps we can/should take to identify and release the affected emails from quarantine?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Would it be possible for Check Point to issue an alert to customers when such incidents occur?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 27 Aug 2024 06:29:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224591#M589</guid>
      <dc:creator>ToffenDask</dc:creator>
      <dc:date>2024-08-27T06:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft false positives outage</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224604#M590</link>
      <description>&lt;P&gt;To clarify are you already using the following related feature or no?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.avanan.com/product-updates/overriding-false-spam-detections-by-microsoft-and-google" target="_blank"&gt;https://www.avanan.com/product-updates/overriding-false-spam-detections-by-microsoft-and-google&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 08:17:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224604#M590</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-27T08:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft false positives outage</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224607#M591</link>
      <description>&lt;P&gt;Yes, we do. These were mis-classified by Microsoft as malware though, so HEC seemed unable to pull them.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 08:32:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224607#M591</guid>
      <dc:creator>ToffenDask</dc:creator>
      <dc:date>2024-08-27T08:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft false positives outage</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224614#M592</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ggg.png" style="width: 970px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27353i9B76EF5349CC9D37/image-size/large?v=v2&amp;amp;px=999" role="button" title="ggg.png" alt="ggg.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 08:45:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224614#M592</guid>
      <dc:creator>ToffenDask</dc:creator>
      <dc:date>2024-08-27T08:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft false positives outage</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224699#M593</link>
      <description>&lt;P&gt;What did TAC advise? I can ask one of my colleagues about this tomorrow, as I am sure he worked with one of our customers who had this sort of an issue last year.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 01:48:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224699#M593</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T01:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft false positives outage</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224704#M594</link>
      <description>&lt;P&gt;It's not entirely a TAC issue as such.&lt;/P&gt;
&lt;P&gt;As I understand we have things in the works to tackle and override the quarantine verdict for 'high confidence' spam in future.&lt;/P&gt;
&lt;P&gt;Also, using Mail Explorer you can manually search the quarantined emails by Microsoft and release those from our portal manually.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 02:17:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224704#M594</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-28T02:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft false positives outage</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224709#M595</link>
      <description>&lt;P&gt;Im happy to hear that Chris, as I heard customers asking about it...quarantine feature for high confidence.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 02:42:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Microsoft-false-positives-outage/m-p/224709#M595</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T02:42:22Z</dc:date>
    </item>
  </channel>
</rss>

