Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ToffenDask
Contributor

Microsoft false positives outage

(I opened a ticket with support for the below issue, but as this forum is collecting cobwebs I thought it wouldn't hurt to share)

Today we have had to manage 10x as many restore requests from our users than normal, undoubtedly due to Microsoft outage EX873252 ("Some users' email messages containing images may have been incorrectly flagged as malware and quarantined"). We expect to be getting quite a few more of these during the day as people are waking up.

Questions are:

  • Were HEC able to pull any of these misclassified emails from quarantine, or is that impossible for those Microsoft detect as malware?

  • Microsoft states in their advisory that they have “automatically replayed” 99% of the affected emails. What would be the expected result of that for us running HEC? Would they automatically be released from quarantine?

  • Are there any proactive steps we can/should take to identify and release the affected emails from quarantine?

  • Would it be possible for Check Point to issue an alert to customers when such incidents occur?

0 Kudos
6 Replies
Chris_Atkinson
Employee Employee
Employee

To clarify are you already using the following related feature or no?

https://www.avanan.com/product-updates/overriding-false-spam-detections-by-microsoft-and-google 

CCSM R77/R80/ELITE
0 Kudos
ToffenDask
Contributor

Yes, we do. These were mis-classified by Microsoft as malware though, so HEC seemed unable to pull them.

0 Kudos
ToffenDask
Contributor

ggg.png

0 Kudos
the_rock
Legend
Legend

What did TAC advise? I can ask one of my colleagues about this tomorrow, as I am sure he worked with one of our customers who had this sort of an issue last year.

Andy

0 Kudos
Chris_Atkinson
Employee Employee
Employee

It's not entirely a TAC issue as such.

As I understand we have things in the works to tackle and override the quarantine verdict for 'high confidence' spam in future.

Also, using Mail Explorer you can manually search the quarantined emails by Microsoft and release those from our portal manually.

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

Im happy to hear that Chris, as I heard customers asking about it...quarantine feature for high confidence.

Andy

0 Kudos
Upcoming Events

    CheckMates Events