Additional Microsoft Defender tools and services that provide security across various platforms and environments
For organization-wide fixes where Salesforce notification mail is being incorrectly labeled as phishing in Microsoft Defender for Office 365, the remediation needs to be done centrally by administrators rather than by end users.
Admin-side options based on the provided guidance:
- Investigate why the messages are flagged as phishing
- Use the Submissions page in Microsoft Defender for Office 365 to submit several of the affected Salesforce messages as false positives (legitimate mail blocked/marked as phishing). This lets Microsoft analyze why they are being classified as phishing and return a verdict.
- Follow the workflow described for legitimate messages: from the User reported or admin-submitted items on the Submissions page, submit to Microsoft for analysis and review the results to understand which policy or signal is causing the phishing verdict.
- Create central allow entries (admin only)
- If the Salesforce sender/domain is confirmed legitimate and the phishing verdict is a false positive, admins can create allow entries for the Salesforce sending domain or specific email addresses in the Tenant Allow/Block List. This is done while or after submitting the messages for analysis.
- Creating allow entries is an admin-only, tenant-wide mitigation and does not require any action from the 8K users. Use this judiciously and only for well-controlled, trusted Salesforce senders.
- Tune anti-phishing protection instead of relying on user actions
- Review and adjust anti-phishing policies in Microsoft Defender for Office 365, especially if recent changes increased aggressiveness and started catching Salesforce notifications as phishing.
- If the Phishing email threshold was recently raised (for example, to Aggressive/More aggressive/Most aggressive), consider tuning it back for the affected users/groups or creating a dedicated policy scope that treats Salesforce notification mail more leniently.
- Ensure that Safe Links, Safe Attachments, and anti-phishing policies are configured correctly and that impersonation/sender spoof settings are not unintentionally catching Salesforce as a spoofed or impersonated sender.
- Fix underlying sender/authentication issues (if applicable)
- If the Salesforce messages are failing SPF/DKIM/DMARC or otherwise appear unauthenticated, this can contribute to phishing/spam classification. Work with the Salesforce/email team to ensure proper email authentication for the Salesforce sending domain.
- Use quarantine and admin review where needed
- If these messages are landing in quarantine, admins can centrally review them on the quarantine review page, submit them to Microsoft for analysis, and release them as needed, again without requiring user action.
This combination—admin submissions for false positives, tenant allow entries for the Salesforce senders, and careful tuning of anti-phishing policies—provides a solution that does not require any corrective steps from the 8K end users.
References:
- How to handle legitimate emails getting blocked (false positives) using Microsoft Defender for Office 365
- Tune anti-phishing protection
- How to handle malicious emails that are delivered to recipients (false negatives) using Microsoft Defender for Office 365
- Frequently asked questions - Anti-spam protection