Office 365 Email - Viewing Security Events

Avanan records the Office 365 Mail detections as security events. The event type depends on the type of policy that created the event. You can handle the security events in different ways, whether they are detected/prevented automatically or discovered by the administrators after not being prevented.

The Events screen shows a detailed view of all the security events.

Events_Office365_Mail

Viewing Security Events for Microsoft Quarantined Emails

To view security events for Microsoft quarantined emails:

  1. Go to Events from the left navigation panel.
  2.  Select the time frame to view the security events.
  3. In the Threat Type filter, select the relevant threat type:
    • Malware for emails Microsoft quarantined because of Malware detection or a block-listed file type.
    • Phishing for emails Microsoft quarantined because of a High Confidence Phishing detection or a Transport Rule.
    • Suspected Phishing for emails Microsoft quarantined because of a Phishing detection.
    • Spam for emails Microsoft quarantined because of High Confidence Spam, Spam, or Bulk detections.
  4. In the Action Taken filter, select Email quarantined.
  5. In the Remediated by filter, select Microsoft.

The Events page shows all the security events for Microsoft quarantined emails. To take action on these security events, see Taking Action on Events.