In Microsoft Defender Tune alert, can I use wildcards or regular expressions for an Email subject condition?

Tilman Schmidt 270 Reputation points
2025-09-03T16:13:06.3766667+00:00

Each time we send out a newsletter, the inevitable autoreplies from a fraction of the recipients trigger a false positive "Mail bombing activity detected" alert from Microsoft Defender. I tried to create a Tune alert rule for resolving these automatically but find preciously little information on how to set up the Condition of such a rule. Specifically, I would like it to match if the subject line of the Email triggering the alert started with "Automatic reply:". However the "Email subject" property only offers the operators "Equals" or "Not equals", not "Starts with".

My hope is that the value field might support regular expressions or at least simple wildcards so I could use a rule: "Email subject" "Equals" "Automatic reply: *" I searched the documentation at https://learn.microsoft.com/en-us/defender-xdr/investigate-alerts?view=o365-worldwide&tabs=settings#tune-an-alert but couldn't find anything on the subject.

Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.