If malicious objects or riskware that was missed is detected later, the Email Security - Server appliance generates an alert and can take retroactive remediation actions on the email. You can configure retroactive remediation on the Email Security - Server appliance for Exchange On-prem and O365 users .
You can configure the Email Security - Server appliance to either quarantine the email or delete it from a user's inbox. After email is quarantined, you can analyze, track, and manage the user's email using the Web UI or CLI.
You can configure automatic remediation and remediation on demand. You configure automatic remediation to either block or delete retroactively detected email. Administrators can view all blocked emails and can release or delete the emails from the quarantine. Administrators can also restore emails that were automatically deleted.
Prerequisites
Administrator or Operator access to the Email Security - Server appliance.
A Microsoft account for the Email Security - Server appliance administrator.
A connection to the Email Security - Server appliance.
To configure retroactive remediation on the Email Security - Server appliance for Exchange On-prem and O365 users and automate the extraction of malicious email, you must first create a Microsoft Office 365 app and configure the app settings for communication and authorization with the appliance.
Complete these tasks in the following order:
You can configure retroactive remediation using the Web UI or CLI: