Email sent by External User are being Quarantined by EOP

Parsian02 20 Reputation points
2025-04-30T08:31:24.4133333+00:00

Hello,

We have recently observed a significant increase in legitimate emails being quarantined by Microsoft 365 Defender (EOP) for both Exchange Online and on-premises users. These emails are being flagged by the anti-spam policies, and this behavior started occurring suddenly across multiple clients.

Based on discussions in several community forums, it appears that this may be related to a recent change or update on Microsoft's end, as many users are experiencing similar issues. This suggests a potential shift in Microsoft's spam filtering algorithms or policy enforcement.

We would appreciate it if you could:

Confirm whether any recent changes have been made by Microsoft to EOP or Defender policies.

Provide any official articles, advisories, or announcements regarding this behavior.

Recommend the appropriate resolution or configuration changes to mitigate these false positives without compromising security.

Thank you for your support.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,531 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.