Microsoft Defender for Office 365
Email and collaboration

Configure connection filtering in cloud organizations

In brief

The documentation now explains that IP Allow List bypasses and SCL 0 are inputs rather than guaranteed final filtering decisions. It also clarifies how to add IP entries and links to mail flow rule guidance.

What Defender admins need to know

Administrators should not assume these settings always bypass or restore spam filtering; review configurations where that outcome is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure connection filtering in cloud organizations

  • Connection filtering section: Select Edit connection filter policy. In the flyout that opens, configure the following settings:

    • Always allow messages from the following IP addresses or address range: This setting is the IP Allow List. Click inIn the IP Allow List box, enter the IP address or address range and press Enter. The entry is added as a value, and then pressseparate item (displayed as a gray box with an X icon). After confirming the ENTER key orentry appears, select the complete value displayed below the box.Save. Valid values are:

      Repeat this step as many times as necessary. To remove an existing entry, select :::image type="icon" source="media/defender-portal-icon-remove-selection.png" border="false"::: next to the entry.

  • Always block messages from the following IP addresses or address range: This setting is the IP Block List. Enter a single IP (for example, 192.168.1.1), IP range (for example, 192.168.0.1-192.168.0.254), or CIDR IP (for example, 192.168.0.1/25) in the box.box and press Enter. The entry is added as a separate item (displayed as a gray box with an X icon). After confirming the entry appears, select Save.

  • Turn on safe list: Enable or disable the use of the safe list that specifies known, good senders to skip spam filtering. To use the safe list, select the check box.

The IP Allow List supports only CIDR IPs with a network mask of /24 to /32.

To skip spam filtering on messages from source email servers in the /1 to /23 range, you can use Exchange mail flow rules (also known as transport rules)use Exchange mail flow rules (transport rules). However, we don't recommend using mail flow rules. Messages are blocked if an IP address in the /1 to /23 CIDR IP range appears on any of Microsoft's proprietary blocklists or non-Microsoft blocklists.

Now that you're fully aware of the potential issues, you can create a mail flow rule with the following settings (at a minimum) to ensure that messages from these IP addresses skip spam filtering:

  • Rule action: Modify the message properties > Set the spam confidence level (SCL) > 0.
  • Rule exception: The sender > domain is > fabrikam.com (only the domain or domains that you want to skip spam filtering).

Adding the source IP address to the IP Allow List is supposed to skip spam filtering for all domains from that source. However, this bypass is an input, not a final decision. Like the Bypass spam filtering (SCL -1) action in a mail flow rule, the IP Allow List bypass is subject to Secure by default, which evaluates the request and might not honor it. Some messages from the source can still be filtered.

The Set the spam confidence level (SCL) to 0 might no longer reliably return those domains to filtering, because the requested SCL value is an input, not a decision.

Scenarios where messages from sources in the IP Allow List are still filtered

Messages from an email server in your IP Allow List are still subject to spam filtering in the following scenarios:

  • Rule condition: Apply this rule if > The sender > IP address is in any of these ranges or exactly matches > (your IP address or addresses).
  • Rule action: Modify the message properties > Set the spam confidence level (SCL) > Bypass spam filtering.

Related content

Preset security policies in cloud organizations