Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
In Microsoft Defender Tune alert, can I use wildcards or regular expressions for an Email subject condition?
Each time we send out a newsletter, the inevitable autoreplies from a fraction of the recipients trigger a false positive "Mail bombing activity detected" alert from Microsoft Defender. I tried to create a Tune alert rule for resolving these automatically but find preciously little information on how to set up the Condition of such a rule. Specifically, I would like it to match if the subject line of the Email triggering the alert started with "Automatic reply:". However the "Email subject" property only offers the operators "Equals" or "Not equals", not "Starts with".
My hope is that the value field might support regular expressions or at least simple wildcards so I could use a rule: "Email subject" "Equals" "Automatic reply: *" I searched the documentation at https://learn.microsoft.com/en-us/defender-xdr/investigate-alerts?view=o365-worldwide&tabs=settings#tune-an-alert but couldn't find anything on the subject.