Spam Emails Delivered to Inbox & Repeated Unauthorized Sign-in Attempts from Foreign Locations (Microsoft 365)

Sorin Advisors LLP 0 Reputation points
2026-02-26T14:21:16.71+00:00

Hello Team,

We are currently facing two major security concerns in our Microsoft 365 tenant.

1️⃣ Spam Filtering Issue

Multiple spam emails are being delivered directly to employee inboxes.

Some legitimate business emails are being marked as spam.

Microsoft Defender for Office 365 is enabled.

Anti-spam policies are active, but filtering does not seem fully effective.

We need guidance on:

Recommended anti-spam policy configuration.

Best practice settings in Microsoft Defender.

How to reduce false positives (important emails marked as spam).

2️⃣ Repeated Unauthorized Sign-in Attempts

All employees are based in India.

However, Entra ID sign-in logs show repeated failed login attempts from foreign countries.

MFA is enabled for all users.

Passwords have been reset.

No successful suspicious login detected so far (only failed attempts).

We want to understand:

How to restrict login access to India only.

How to block foreign IP addresses.

Whether this is automated bot traffic or a real targeted attack.

Recommended Conditional Access configuration.

We would appreciate detailed guidance to strengthen our tenant security.

Thank you.

Microsoft 365 and Office | Microsoft 365 Defender | Other | Windows
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-02-26T14:21:43.92+00:00

    For spam and sign-in protection, use the built-in capabilities of Microsoft 365 and Microsoft Defender for Office 365, and tune them using anti-spam policies and related threat policies.

    1. Spam filtering and false positives

    • Anti-spam is always on for cloud mailboxes and is controlled by anti-spam policies (default + any custom policies). • The default anti-spam policy applies to all recipients. • Custom anti-spam policies can be scoped to specific users, groups, or domains and ordered by priority; processing stops at the first applicable policy. • If Standard/Strict preset security policies are enabled, they take precedence over custom and default anti-spam policies.

    • Recommended approach • Prefer using Standard and/or Strict preset security policies for most users instead of many custom policies. These have recommended anti-spam settings preconfigured and unmodifiable. • For advanced tuning, configure anti-spam policies in the Microsoft Defender portal (https://security.microsoft.com → Email & collaboration → Policies & rules → Threat policies → Anti-spam) or via Exchange Online PowerShell.

    • Key anti-spam behaviors • Messages are classified with spam verdicts based on spam confidence level (SCL): • Spam: SCL 5–6 • High confidence spam: SCL 7–9 • Bulk: based on bulk complaint level (BCL) • Phishing / High confidence phishing: high confidence phishing is always quarantined and cannot be user-released. • Quarantine retention defaults to 15 days, and 30 days in Standard/Strict recommendations. • ZAP (zero-hour auto purge) is enabled by default for spam and phishing in recommended settings.

    • Reducing false positives (legitimate mail marked as spam) • Use message headers to understand why a message was marked as spam or skipped filtering. See “Anti-spam message headers” to interpret SCL/BCL and ASF decisions. • If a message is incorrectly classified: • Report it as a false positive using the Submissions page in the Microsoft Defender portal or from Outlook. This trains the service and can create temporary allow entries. • Follow the step-by-step guides for handling false positives in Microsoft Defender for Office 365. • Avoid overusing Allowed senders/domains in anti-spam policies: • Allowed senders/domains bypass most protection (except malware and high confidence phishing) and SPF/DKIM/DMARC checks, which significantly increases risk. • Never add common domains like microsoft.com or office.com to allowed domains. • If an allowed domain must be kept long term, ensure the sender’s SPF is correct and DMARC policy is p=reject. • Prefer using the Tenant Allow/Block List and spoof intelligence for specific spoofing/legitimacy scenarios instead of broad allow lists.

    • Reducing spam delivered to inbox • Ensure Standard or Strict preset policies are enabled and applied to all users where possible. • Review Advanced Spam Filter (ASF) “Mark as spam” settings (for example, SPF hard fail, object tags in HTML, sensitive words). These settings set SCL to 6 (Spam) or higher depending on configuration. • If mail is routed through a non-Microsoft gateway first, use mail flow rules or Enhanced Filtering for connectors as documented, and avoid disabling spam filtering entirely. Spam filtering cannot be fully turned off, but mail flow rules can lower SCL for specific trusted flows if absolutely necessary. • Use the FAQ and recommended settings guidance to align with best practices.

    1. Repeated unauthorized sign-in attempts from foreign locations

    The context provided focuses on email and anti-spam; it does not include detailed Entra ID Conditional Access or geo-restriction configuration steps. However, the following points are supported:

    • Sign-in protection posture • MFA is already enabled and passwords have been reset, which significantly reduces risk from password-guessing and basic bot attacks. • Repeated failed sign-ins from foreign locations are commonly due to automated bot traffic rather than successful compromise, especially when no suspicious successful sign-ins are observed.

    • Next steps (high level, based on available context) • Continue to rely on MFA and strong passwords as primary defenses. • Use Microsoft 365 security features (Defender for Office 365 and related threat policies) as part of the overall protection stack. • For detailed Conditional Access, country-based access restrictions, and IP blocking configuration, refer to Entra ID and Conditional Access documentation outside of this context.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.