(I opened a ticket with support for the below issue, but as this forum is collecting cobwebs I thought it wouldn't hurt to share)
Today we have had to manage 10x as many restore requests from our users than normal, undoubtedly due to Microsoft outage EX873252 ("Some users' email messages containing images may have been incorrectly flagged as malware and quarantined"). We expect to be getting quite a few more of these during the day as people are waking up.
Questions are:
Were HEC able to pull any of these misclassified emails from quarantine, or is that impossible for those Microsoft detect as malware?
Microsoft states in their advisory that they have “automatically replayed” 99% of the affected emails. What would be the expected result of that for us running HEC? Would they automatically be released from quarantine?
Are there any proactive steps we can/should take to identify and release the affected emails from quarantine?
Would it be possible for Check Point to issue an alert to customers when such incidents occur?