Managing remediation policies

Prev Next

Important

Remediation policies are available only to customers using inline, inline with hygiene, MS365 Native, MS365 Native with hygiene, Google Workspace Native, or Google Workspace Native with hygiene with Office 365 (O365) or Google Workspace.

Remediation policies specify what actions you or Email Security — Cloud can retroactively perform in your organization's Office 365 or Gmail inboxes. For SMTP there are two types, or modes, of remediation policies and four actions that can be assigned to both modes. For MS365 API and Google Workspace API there are three types, or modes, of remediation policies and four actions that can be assigned to the modes.

An SMTP remediation policy can be set to Retroactive(Auto) mode, Manual mode, or both. An MS365 API or Google Workspace API remediation policy can be set to Retroactive(Auto) mode, Manual mode, Native mode, or all three.

A remediation policy set to Retroactive(Auto) mode will automatically execute the policy actions assigned to it when a message is retroactively marked as malicious by Email Security — Cloud. A remediation policy set to Manual mode lets you quarantine, move, monitor, or delete any message in the Email Trace page. You can manually remediate a message using the action defined in the policy or override the policy configuration to take a different action. A remediation policy set to Native mode will enable automated email scanning and remediation. If you set a remediation policy to more than one mode, Email Security — Cloud automatically executes policy actions, but you can also manually remediate messages in the email trace. You can also apply default policy actions for advanced threats, viruses, and spam in the Email Trace page.

Note

You can manually remediate up to 100 messages at a time from the Email Trace page.

Important

For MS365 native, the following folders are not scanned by Email Security — Cloud: Conversation History, Deleted Items, Drafts, Junk Email, Local Failures, Outbox, Recoverable Items > Deletions, Search Folders, Sent Items, and Sync Issues.

For Google Workspace native, the following folders are not scanned by Email Security — Cloud: SENT, TRASH, DRAFT, CHAT, and SPAM.

Important

For information on the permissions needed for Retroactive(Auto) remediation, see the Community article on this topic.

The four actions available for remediation policies are Quarantine, Move, Permanent Delete, and Take No Action (Monitor). A remediation policy set to Quarantine will retroactively move a message from O365 inboxes to the Email Security — Cloud quarantine.

A remediation policy set to Move will retroactively move a message to the Junk or Deleted Items folder, or a custom folder that you specify. A remediation policy set to Permanent Delete will retroactively delete a message from the user's inbox. A remediation policy set to Take No Action (Monitor) will not perform any immediate action, but allows you to monitor the message.

You can select an action for each message type: Advanced threats, Riskware, Viruses, or spam. The message types available depend on your integration type and license.

You can only select one action for each message type within a remediation policy. For example, an automatic remediation policy set to move will automatically move messages retroactively identified as malicious. A manual remediation policy set to move, however, lets you manually move, quarantine, or delete messages within your inbox from the Email Trace page. If your remediation policy is set to both automatic and manual mode, you can manually override the action automatically executed against a message. For example, if an automatic and manual mode remediation policy automatically quarantines a message, you can later locate the message in the Email Trace and manually move or delete it, overriding the quarantine.

Note

Email recovery may still be possible in Exchange Online Protection when the policy action is set to Permanent Delete. A policy setting in Exchange Online Protection allows the user to recover emails for a set number of days. For more information, see the Microsoft documentation.

You must add a verified authorization to a remediation policy to execute any actions in your organization's O365 or Gmail inboxes. You can use the same authorization for multiple remediation policies. For instructions on creating and verifying an authorization for a remediation policy, see Adding authorizations and Verifying authorizations through your Microsoft O365 account. You can add an unverified authorization to a remediation policy, but no actions will be taken in your inbox until it is verified. For more information on authorizations, see Configuring authorizations.

Emails affected by remediation policies can be searched for in the Quarantine and Email Trace pages. An email retroactively remediated by a remediation policy includes a tag in the Email Trace and Quarantine pages. A message is tagged either "Retroactive(Auto) Remediation" or "Manual Remediation", depending on the mode of action. Details about a remediation policy's actions are also accessible in Quarantine Message Details. The remediated email will also appear in the next email digest you receive. See Email trace and Quarantine message details for more information.

Note

A remediation policy can be applied to email distribution lists. Policy actions apply to all recipients concurrently.

Failed remediation will be retried 10 times. The first retry will begin 5 seconds after the failure. Subsequent retries will be attempted after exponentially increasing intervals.

To create a remediation policy:

  1. In the Configuration > Policies page, select Create Policy.

  2. Next to Traffic Type, select Inbound.

  3. Select an integration type.

  4. Under Rule Type, select Remediation.

  5. Enter a policy name and description (optional).

  6. Click Create. The policy configuration page appears.

  7. Click Manage next to Configuration.

  8. Select a platform from the drop-down list.

  9. Next to Authorization, Click Select and choose a verified authorization from the drop-down list.

    1. (Optional) Click Add New Authorization to create a new authorization. The authorization will not function until you verify it.

  10. Select one or both policy modes.

    Note

    For MS365 API and Google Workspace API policies, select one or all policy modes: Manual, Native, and Retroactive(Auto).

  11. Select a policy action for Advanced Threats.

    1. If you select the Move policy action, a new field appears. Open the Policy Folder drop-down menu and select a folder where messages will be moved to.

      The folder options for MS365 are Junk Email, Deleted Items, or Custom. The folder options for Google Workspace are Spam, Trash, or Custom.

    2. Select Custom to specify an alternate folder. and enter the name of that folder in the Custom Folder field. If you enter a folder that does not exist in your Office 365 email account, the folder will automatically be created if your authorization has been verified.

  12. Select a policy action for Spam, if applicable.

  13. For MS365 API and Google Workspace API policies, select a policy action for Riskware.

  14. For MS365 API and Google Workspace API polices, select a policy action for Viruses.

  15. Enable end user notifications (optional). End users will receive email notifications when messages are remediated. Administrators can configure the details included in the notification. This feature is disabled by default.

    A text template is shown if end user notifications are enabled. The notification subject and notification body are both editable. The variables and their descriptions are listed to the right.

  16. Click Save.

Important

Individual domains included in domain groups do not automatically inherit the remediation policies associated with the domain group's configuration. Remediation policies must be applied to domains individually for remediation actions to be properly executed.