What you need to know
Does a custom anti-malware policy configure protection for mail leaving a cloud mailbox?
Potentially affected
Organizations reviewing anti-malware policy settings for cloud mailboxes and outbound messages.
DSE recommendation
Give outbound message handling its own review against the default anti-malware policy rather than inferring it from a custom recipient policy.
Source facts
Microsoft distinguishes mail direction: the default anti-malware policy covers inbound and outbound messages, while custom anti-malware policies cover inbound messages only. The default policy cannot be disabled. Administrator notifications described in this configuration guide are sent only for attachments classified as malware. Those boundaries matter when someone expects a custom-policy change or an absent notification to describe outgoing protection. Microsoft Learn.
Applicability
Review cloud-mailbox anti-malware configuration, not an assumption about a different message protection feature. Identify the sending mailbox, recipient direction, policy being edited, and notification setting. Keep a custom policy’s recipient targeting separate from the outgoing-mail question.
DSE recommendation
Give outbound message handling its own review against the default anti-malware policy rather than inferring it from a custom recipient policy. Have the messaging owner document the intended outgoing action and the administrator who should receive relevant notifications. Review the actual classification when a notice is absent; do not use notification volume alone as a measure of protection.
Verification
Plan separately approved internal-to-internal, internal-to-external, and external-to-internal tests using Microsoft’s documented safe-testing guidance. Preserve direction, effective settings, message outcome, classification, and expected notification recipient for each case. Investigate any mismatch before changing notification recipients or adding more custom policies. Keep the outcome evidence tied to the tested flow so an inbound success is not reused as the outbound acceptance record.
Official references
Microsoft Learn: Configure anti-malware policies for cloud mailboxes. Source reviewed September 9, 2026.
Review the official source
Configure anti-malware policies for email - Microsoft Defender for Office 365 | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE