How Policies And Protections Are Combined
In brief
A footnote was revised for organizations using a non-Microsoft security service or device before Microsoft 365. It references ARC and Enhanced Filtering for Connectors and advises checking service availability.
What Defender admins need to know
Administrators using such services should review the updated guidance when configuring mail flow and authentication.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
|Bulk|Organization wins: Email delivered to mailbox|Filter wins: Email delivered to user's Junk Email folder| |Not spam|Organization wins: Email delivered to mailbox|Organization wins: Email delivered to user's Junk Email folder|
* Organizations that use a non-Microsoft security service or device in front of Microsoft 365 should consider using Authenticated Received Chain (ARC) (contact the service for availability) and Enhanced Filtering for Connectors (also known as skip listing) instead of an SCL=-1 mail flow rule.bypass spam filtering mail flow rules (spam confidence level or SCL -1). These improved methods reduce email authentication issues and encourage defense-in-depth email security.
- IP Allow List and IP Block List in connection filtering:
@@ -154,7 +154,7 @@ Organization allows and blocks are able to override some filtering stack verdict |Bulk|**Organization wins**: Email delivered to mailbox|**Filter wins**: Email delivered to user's Junk Email folder| |Not spam|**Organization wins**: Email delivered to mailbox|**Organization wins**: Email delivered to user's Junk Email folder| - <sup>\*</sup> Organizations that use a non-Microsoft security service or device in front of Microsoft 365 should consider using [Authenticated Received Chain (ARC)](email-authentication-arc-configure.md) (contact the service for availability) and [Enhanced Filtering for Connectors (also known as skip listing)](/exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/enhanced-filtering-for-connectors) instead of an SCL=-1 mail flow rule. These improved methods reduce email authentication issues and encourage [defense-in-depth](step-by-step-guides/defense-in-depth-guide.md) email security.+ <sup>\*</sup> Organizations that use a non-Microsoft security service or device in front of Microsoft 365 should consider using [Authenticated Received Chain (ARC)](email-authentication-arc-configure.md) (contact the service for availability) and [Enhanced Filtering for Connectors (also known as skip listing)](/exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/enhanced-filtering-for-connectors) instead of [bypass spam filtering mail flow rules](/exchange/security-and-compliance/mail-flow-rules/use-rules-to-set-scl) (spam confidence level or SCL -1). These improved methods reduce email authentication issues and encourage [defense-in-depth](step-by-step-guides/defense-in-depth-guide.md) email security. - IP Allow List and IP Block List in [connection filtering](connection-filter-policies-configure.md): 