{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/",
        "slug": "dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/"
        },
        "title": "Review outbound malware handling separately from custom inbound mail policies",
        "summary": "Does a custom anti-malware policy configure protection for mail leaving a cloud mailbox?",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:20+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 234,
        "potentially_affected": "Organizations reviewing anti-malware policy settings for cloud mailboxes and outbound messages.",
        "dse_recommendation": "Give outbound message handling its own review against the default anti-malware policy rather than inferring it from a custom recipient policy.",
        "primary_source": {
            "name": "Configure anti-malware policies for email - Microsoft Defender for Office 365 | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-office-365/anti-malware-policies-configure",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft distinguishes mail direction: the default anti-malware policy covers inbound and outbound messages, while custom anti-malware policies cover inbound messages only. The default policy cannot be disabled. Administrator notifications described in this configuration guide are sent only for attachments classified as malware. Those boundaries matter when someone expects a custom-policy change or an absent notification to describe outgoing protection. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/anti-malware-policies-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review cloud-mailbox anti-malware configuration, not an assumption about a different message protection feature. Identify the sending mailbox, recipient direction, policy being edited, and notification setting. Keep a custom policy&#8217;s recipient targeting separate from the outgoing-mail question.</p>\n<h2>DSE recommendation</h2>\n<p>Give outbound message handling its own review against the default anti-malware policy rather than inferring it from a custom recipient policy. Have the messaging owner document the intended outgoing action and the administrator who should receive relevant notifications. Review the actual classification when a notice is absent; do not use notification volume alone as a measure of protection.</p>\n<h2>Verification</h2>\n<p>Plan separately approved internal-to-internal, internal-to-external, and external-to-internal tests using Microsoft&#8217;s documented safe-testing guidance. Preserve direction, effective settings, message outcome, classification, and expected notification recipient for each case. Investigate any mismatch before changing notification recipients or adding more custom policies. Keep the outcome evidence tied to the tested flow so an inbound success is not reused as the outbound acceptance record.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-office-365/anti-malware-policies-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure anti-malware policies for cloud mailboxes</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft distinguishes mail direction: the default anti-malware policy covers inbound and outbound messages, while custom anti-malware policies cover inbound messages only. The default policy cannot be disabled. Administrator notifications described in this configuration guide are sent only for attachments classified as malware. Those boundaries matter when someone expects a custom-policy change or an absent notification to describe outgoing protection. Microsoft Learn.\nApplicability\nReview cloud-mailbox anti-malware configuration, not an assumption about a different message protection feature. Identify the sending mailbox, recipient direction, policy being edited, and notification setting. Keep a custom policy’s recipient targeting separate from the outgoing-mail question.\nDSE recommendation\nGive outbound message handling its own review against the default anti-malware policy rather than inferring it from a custom recipient policy. Have the messaging owner document the intended outgoing action and the administrator who should receive relevant notifications. Review the actual classification when a notice is absent; do not use notification volume alone as a measure of protection.\nVerification\nPlan separately approved internal-to-internal, internal-to-external, and external-to-internal tests using Microsoft’s documented safe-testing guidance. Preserve direction, effective settings, message outcome, classification, and expected notification recipient for each case. Investigate any mismatch before changing notification recipients or adding more custom policies. Keep the outcome evidence tied to the tested flow so an inbound success is not reused as the outbound acceptance record.\nOfficial references\nMicrosoft Learn: Configure anti-malware policies for cloud mailboxes. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft distinguishes mail direction: the default anti-malware policy covers inbound and outbound messages, while custom anti-malware policies cover inbound messages only. The default policy cannot be disabled. Administrator notifications described in this configuration guide are sent only for attachments classified as malware. Those boundaries matter when someone expects a custom-policy change or an absent notification to describe outgoing protection. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/anti-malware-policies-configure).\n\n## Applicability\n\nReview cloud-mailbox anti-malware configuration, not an assumption about a different message protection feature. Identify the sending mailbox, recipient direction, policy being edited, and notification setting. Keep a custom policy’s recipient targeting separate from the outgoing-mail question.\n\n## DSE recommendation\n\nGive outbound message handling its own review against the default anti-malware policy rather than inferring it from a custom recipient policy. Have the messaging owner document the intended outgoing action and the administrator who should receive relevant notifications. Review the actual classification when a notice is absent; do not use notification volume alone as a measure of protection.\n\n## Verification\n\nPlan separately approved internal-to-internal, internal-to-external, and external-to-internal tests using Microsoft’s documented safe-testing guidance. Preserve direction, effective settings, message outcome, classification, and expected notification recipient for each case. Investigate any mismatch before changing notification recipients or adding more custom policies. Keep the outcome evidence tied to the tested flow so an inbound success is not reused as the outbound acceptance record.\n\n## Official references\n\n[Microsoft Learn: Configure anti-malware policies for cloud mailboxes](https://learn.microsoft.com/en-us/defender-office-365/anti-malware-policies-configure). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review outbound malware handling separately from custom inbound mail policies",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/",
                "headline": "Review outbound malware handling separately from custom inbound mail policies",
                "description": "Does a custom anti-malware policy configure protection for mail leaving a cloud mailbox?",
                "abstract": "Does a custom anti-malware policy configure protection for mail leaving a cloud mailbox?",
                "articleBody": "Source facts\nMicrosoft distinguishes mail direction: the default anti-malware policy covers inbound and outbound messages, while custom anti-malware policies cover inbound messages only. The default policy cannot be disabled. Administrator notifications described in this configuration guide are sent only for attachments classified as malware. Those boundaries matter when someone expects a custom-policy change or an absent notification to describe outgoing protection. Microsoft Learn.\nApplicability\nReview cloud-mailbox anti-malware configuration, not an assumption about a different message protection feature. Identify the sending mailbox, recipient direction, policy being edited, and notification setting. Keep a custom policy’s recipient targeting separate from the outgoing-mail question.\nDSE recommendation\nGive outbound message handling its own review against the default anti-malware policy rather than inferring it from a custom recipient policy. Have the messaging owner document the intended outgoing action and the administrator who should receive relevant notifications. Review the actual classification when a notice is absent; do not use notification volume alone as a measure of protection.\nVerification\nPlan separately approved internal-to-internal, internal-to-external, and external-to-internal tests using Microsoft’s documented safe-testing guidance. Preserve direction, effective settings, message outcome, classification, and expected notification recipient for each case. Investigate any mismatch before changing notification recipients or adding more custom policies. Keep the outcome evidence tied to the tested flow so an inbound success is not reused as the outbound acceptance record.\nOfficial references\nMicrosoft Learn: Configure anti-malware policies for cloud mailboxes. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:26:20+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-336-review-outbound-malware-handling-separately-from-custom-inbound-mail-policies/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review outbound malware handling separately from custom inbound mail policies"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Briefing",
                    "Information priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 234,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure anti-malware policies for email - Microsoft Defender for Office 365 | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-office-365/anti-malware-policies-configure"
                }
            }
        ]
    }
}