Enhanced infrastructure and expanded capacity in Trellix Email Security - Cloud 2025.2 deliver faster performance and stronger detection capabilities.
Announcements
Trellix Email Security Cloud Outlook Add-in Consent Required
Trellix Email Security - Cloud has updated the Outlook add-in as part of this release, to align with the ongoing Microsoft changes related to ending support for legacy tokens in Exchange Online. This is a reminder that you need to grant consent to your Outlook add-in to ensure that it continues to function properly. If you have granted the consent already, no further action is needed.
For more details, see Support Notice.
Advanced Threats tab renamed to Alerts tab
The Advanced Threats tab is now renamed as Alerts tab. The appearance, location, features and contents of the tab remains same.
Caution
The Advanced Threat tab will be referred to as the Alerts tab henceforth in this release note and other Email Security - Cloud documents and supporting documents starting from this release.
End-of-life for Alerts version 1 APIs
The existing set of Alerts APIs will be deprecated by the end of 2025. A new set of Alerts APIs is introduced in this release. Please check the New features section for the new set of Alerts APIs.
The older set of APIs will be called as Version 1/V1 and the new set of APIs will be called as Version 2/V2.
New features
Performance and detection have been improved through infrastructure and capacity enhancements to Trellix Email Security - Cloud 2025.2.
Riskware tab merged with the Alerts tab
The Riskware tab is no longer available on the Email Security - Cloud Web UI. Its contents and features have been merged with the Alerts tab.
Riskware alerts will be categorised under the new alert type, Riskware.
For more details, see Alerts.
Second set of Alerts APIs
You can now use a second set of Alerts REST APIs to request for the following details. This new set of APIs will be referred to as Version 2/V2 :
Search alerts
View alert details
Download alert malware, packet capture and case files
Read alerts
Acknowledge alerts
Delete alerts
Retrieve URL click reports
Note
V2 alert IDs have a new format. V2 APIs will not accept V1 alert IDs.
For more details, see Alerts APIs version 2.
Query to filter alerts
You can now use queries to create a filter to search for alerts in the Alerts table. This feature is available only in the advanced mode.
In the existing basic mode you can select a filter by clicking its respective drop-down menu. You can also select the Add More Filters link.
For more details, see Filtering alerts.
Bulk remediation on the email trace page
Emails with a remediation policy can now be remediated together in bulk in the Email Trace page. You can apply a default policy action or choose how the message/s will be remediated.
You can bulk remediate emails appearing in a single page together. The maximum emails that can be bulk remediated is 10000.
For more details, see Remediation.
Policy association for email routing policies
You can now manage a policy for all the domain groups and domains in a single table via the Policies page for email routing policies. This feature allows you to manage policy inheritance from domain groups to child domains. You can also associate and dissociate policies from the domain groups, child domains and standalone domains.
Note
This feature is only available for Remediation, Riskware, Advance URL Defense and Email Routing policies.
For more details, see Associating policies.
Phishing simulator updates
For more details, see Phishing simulator.
Licensed feature: Phishing simulator is now an add-on feature. It will be enabled for all customers (except for federated organizations) and it has a limit of 5 user per campaign. A warning banner will now appear in the campaigns page for non-licensed users.
Malicious QR code template: You can now add two types of templates to a phishing campaign - malicious URL (existing) and malicious QR code (new). In the first type, the user needs to click on a URL. In the second type, the user needs to scan a QR code.
Importing and exporting user lists: You can now upload a user list in .csv format while creating a phishing campaign. You need to make sure that the CSV file has 2 columns - name and email.
Caution
The Upload CSV and Import Users options will be disabled in the default version. You need to buy a license to remove the limitations.
You can also export the user list of a phishing campaign as a .csv file from the View Campaign page. The export CSV button will be available only when the campaign is closed.
Search closed campaigns: You can now use the search box to search for closed campaigns using email addresses of users.
Export repeat offenders widget details: You can download the details appearing in the repeat offenders widget in the Phishing Simulator overview page in .csv format.
Enhancements
New alert types
Alerts in the Alerts tab can now be categorised under two new types - Riskware and Other.
Riskware alerts will be categorised under the new alert type, Riskware. Alert types which cannot be categorised under Riskware and other existing alert types, will be marked as Other.
For more details, see Alerts.
Verifying authorizations through Microsoft O365 account
While verifying a newly created authorization through your Microsoft O365 account, if the required permissions are missing, the authorization is not saved and the missing permissions are listed.
Changes in the Alerts downloadable file
When you download an alerts file in CSV format, you can now see the columns in the following sequence:
Alert ID - Message ID - Date & Time - From - Recipients - Subject - Malware Type - Malware Name - Malware MD5 - Source IP - Source Country - Email Status - View - Threat Type - Threat Type Description - Is Retroactive Alert - Riskware File Type - Riskware Rule ID.
Action field update for retroactive alerts
The Action field previously displayed Blocked for retroactive alerts synced into CMS from the Email Security - Cloud. Newly generated retroactive alerts will now be marked as Notified instead of Blocked.
Retroactive email status removed
The following email statuses are no longer available on the Email Security - Cloud Web UI as well as API.
The status for processed emails from this release can only be quarantined, scanned, deleted, or, dropped (OOB).
For more details, see Email trace filters.
Delivered(Retroactive)
Dropped(OOB Retroactive)