Microsoft Defender for Office 365
Email and collaboration

Submissions Admin

In brief

The page updates headings and submission instructions, formats notes consistently, documents language selection for default automatic notification templates, and adds related links.

What Defender admins need to know

Administrators should note that default-template notifications use each user's preferred Outlook language; custom templates are unaffected. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

For other ways that admins can report messages to Microsoft in the Defender portal, see Related reporting settings for admins.

What do you need to know before you begin?Prerequisites

Before you use the Submissions page, review the following requirements and considerations:

  • Same submissions in a 24 hour period: Three submissions

  • Same submissions in a 15-minute period: One submission

  • If the User reported settings in the organization send user reported messages (email and Microsoft Teams) to Microsoft (exclusively or in addition to the reporting mailbox), we do the same checks as when admins submit messages to Microsoft for analysis from the Submissions page. So,page, so submitting or resubmitting messages to Microsoft is useful to admins only for messages that have never been submitted to Microsoft, or when you disagree with the original verdict.

  • A Files tab is available on the Submissions page only in organizations with Microsoft Defender or Microsoft Defender for Endpoint Plan 2. For information and instructions to submit files from the Files tab, see Submit files in Microsoft Defender for Endpoint.

    • Choose at least one recipient who had an issue: Specify the recipients to run a policy check against. The policy check determines if the email bypassed scanning due to user or organization policies or override.

    • Why are you submitting this message to Microsoft?: Select one of the following values:You can select either:

      • It appears suspicious: Select this value only when you don't know or you're unsure of the message verdict and you would like to get a verdict from Microsoft. Select Submit, and then go to Step 6.

      or

      • I've confirmed it's a threat: In all other cases, select this value after you've already determined the message verdict as malicious. Select one of the following values in the Choose a category section that appears:

        • Phish
        • Malware

        :::image type="content" source="media/admin-submission-email-block.png" alt-text="Submit a false negative (bad) email to Microsoft for analysis on the Submissions page in the Defender portal." lightbox="media/admin-submission-email-block.png":::

  1. On the second page of the Submit to Microsoft for analysis flyout that opens, do one of the following steps:you can either:

    • Select Submit.

    or

    • Select Block all emails from this sender or domain: This option creates a block entry for the sender domain or email address in the Tenant Allow/Block List. For more information about the Tenant Allow/Block List, see Manage allows and blocks in the Tenant Allow/Block List.

      After you select this option, the following settings are available:

    • Why are you submitting this email attachment to Microsoft?: Select one of the following values:

      • It appears suspicious: Select this value if you're unsure and you want a verdict from Microsoft, select Submit, and then go to Step 6.

      or

      • I've confirmed it's a threat: Select this value if you're sure that the item is malicious, and then select one of the following values in the Choose a category section that appears:

        • Phish
        • Malware

        :::image type="content" source="media/admin-submission-file-block.png" alt-text="Submit a false negative (bad) email attachment to Microsoft for analysis on the Submissions page in the Defender portal." lightbox="media/admin-submission-file-block.png":::

  2. On the second page of the Submit to Microsoft for analysis flyout that opens, doyou can choose one of the following steps:following:

    • Select Submit.

    or

    • Select Block this file: This option creates a block entry for the file in the Tenant Allow/Block List. For more information about the Tenant Allow/Block List, see Manage allows and blocks in the Tenant Allow/Block List.

      After you select this option, the following settings are available:

    • Why are you submitting this URL to Microsoft?: Select one of the following values:

      • It appears suspicious: Select this value if you're unsure and you want a verdict from Microsoft, select Submit, and then go to Step 6.

      or

      • I've confirmed it's a threat: Select this value if you're sure that the item is malicious, and then select one of the following values in the Choose a category section that appears:

        • Phish
        • Malware

        :::image type="content" source="media/admin-submission-url-block.png" alt-text="Submit a false negative (bad) URL to Microsoft for analysis on the Submissions page in the Defender portal." lightbox="media/admin-submission-url-block.png":::

  3. On the second page of the Submit to Microsoft for analysis flyout that opens, doselect one of the following steps:options:

    • Select Submit.

    or

    • Select Block this URL: This option creates a block entry for the URL in the Tenant Allow/Block List. For more information about the Tenant Allow/Block List, see Manage allows and blocks in the Tenant Allow/Block List.

      After you select this option, the following settings are available:

    • Why are you submitting this message to Microsoft?: Select one of the following values:

      • It appears clean: Select this value only when you don't know or you're unsure of the message verdict and you would like to get a verdict from Microsoft. Select Submit, and then go to Step 6.

    • or

      • I've confirmed it's clean: In all other cases, select this value after you've already determined the message verdict as clean. Select Next.

    :::image type="content" source="media/admin-submission-email-allow.png" alt-text="Submit a false positive (good) email to Microsoft for analysis on the Submissions page in the Defender portal." lightbox="media/admin-submission-email-allow.png":::

  4. On the second page of the Submit to Microsoft for analysis flyout that opens, doselect one of the following steps:options:

    • Select Submit.

    or

    • Select Allow this message: This option creates an allow entry for the elements of the message in the Tenant Allow/Block List. For more information about the Tenant Allow/Block List, see Manage allows and blocks in the Tenant Allow/Block List.

      After you select this option, the following settings are available:

    • File: Select Browse files to find and select the file to submit.

    • Why are you submitting the message to Microsoft?: Select one of the following values:options:

      • It appears clean: Select this value if you're unsure and you want a verdict from Microsoft, select Submit, and then go to Step 6.

    • or

      • I've confirmed it's clean: Select this value if you're sure that the item is clean, and then select Next.

    :::image type="content" source="media/admin-submission-file-allow.png" alt-text="Submit a false positive (good) email attachment to Microsoft for analysis on the Submissions page in the Defender portal." lightbox="media/admin-submission-file-allow.png":::

  5. On the second page of the Submit to Microsoft for analysis flyout that opens, doselect one of the following steps:options:

    • Select Submit.

    or

    • Select Allow this file: This option creates a allow entry for the file in the Tenant Allow/Block List. For more information about the Tenant Allow/Block List, see Manage allows and blocks in the Tenant Allow/Block List.

      After you select this option, the following settings are available:

Report good URLs to Microsoft

For URLs reported as false positives, we allow subsequent messages that contain variations of the original URL. For example, you use the Submissions page to report the incorrectly blocked URL www.contoso.com/abc. If your organization later receives a message that contains the URL (for exampleexample, but not limited to: www.contoso.com/abc, www.contoso.com/abc?id=1, www.contoso.com/abc/def/gty/uyt?id=5, or www.contoso.com/abc/whatever), the message won't be blocked based on the URL. In other words, you don't need to report multiple variations of the same URL as good to Microsoft.

  1. In the Defender portal at https://security.microsoft.com, go to Actions & submissions > Submissions. Or, to go directly to the Submissions page, use https://security.microsoft.com/reportsubmission.

    • URL: Enter the full URL (for example, https://www.fabrikam.com/marketing.html), and then select it in the box that appears. You can also provide a top level domain (for example, https://www.fabrikam.com/*), and then select it in the box that appears. You can enter up to 50 URL at once.

    • Why are you submitting this URL to Microsoft?: Select one of the following values:options:

      • It appears clean: Select this value if you're unsure and you want a verdict from Microsoft, select Submit, and then go to Step 6.

      or

      • I've confirmed it's clean: Select this value if you're sure that the item is clean, and then select Next.

        :::image type="content" source="media/admin-submission-url-allow.png" alt-text="Submit a false positive (good) URL to Microsoft for analysis on the Submissions page in the Defender portal." lightbox="media/admin-submission-url-allow.png":::

  2. On the second page of the Submit to Microsoft for analysis flyout that opens, doselect one of the following steps:options:

    • Select Submit.

    or

    • Select Allow this URL: This option creates an allow entry for the URL in the Tenant Allow/Block List. For more information about the Tenant Allow/Block List, see Manage allows and blocks in the Tenant Allow/Block List.

      After you select this option, the following settings are available:

Notes:

  • User reported messages that are sent to Microsoft only or to Microsoft and the reporting mailbox

    In organizations with Microsoft Defender for Office 365 Plan 1 or Plan 2 (add-on licenses or included in subscriptions like Microsoft 365 E5), admins can also see user reported messages in Microsoft Teams.

    - **I've confirmed it's clean**: Select this value if you're sure that the item is clean, and then select **Next**.
    
      On the next page of the flyout, doselect one of the following steps:options:
    
      - Select **Submit**, and then select **Done**.
    
      or
    
      - Select **Allow this message**: This option creates an allow entry for the elements of the message in the Tenant Allow/Block List. For more information about the Tenant Allow/Block List, see [Manage allows and blocks in the Tenant Allow/Block List](tenant-allow-block-list-about.md).
    
      After you select this option, the following settings are available:
    
      Select **Next**.
    
      On the next page of the flyout, doselect one of the following steps:options:
    
      - Select **Submit**, and then select **Done**.
    
      or
    
      - Select **Block all emails from this sender or domain**: This option creates a block entry for the sender domain or email address in the Tenant Allow/Block List. For more information about the Tenant Allow/Block List, see [Manage allows and blocks in the Tenant Allow/Block List](tenant-allow-block-list-about.md).
    
      After you select this option, the following settings are available:
    

    After an admin submits a user reported message to Microsoft from the User reported tab, admins can use the :::image type="icon" source="media/defender-portal-icon-mark-and-notify.png" border="false"::: Mark as and notify action to mark the message with a verdict and send a templated notification message to the user who reported the message.

    When automatic notifications use the default notification template, users receive the notification in their preferred language based on their Outlook language settings. Custom notification templates configured by admins aren't affected.

    • Available verdicts for email messages:

      • No threats found
      • Phishing
    • :::image type="icon" source="media/defender-portal-icon-take-actions.png" border="false"::: Take actions (email messages only): This action starts the same Action wizard that's available on the Email entity page. For more information, see Actions on the Email entity page.

    • :::image type="icon" source="media/defender-portal-icon-view-alert.png" border="false"::: View alert. An alert is triggered when an admin submission is created or updated. Selecting this action takes you to the details of the alert.

    Related content