G DATA Phishing Simulation

What must be considered when whitelisting in Microsoft hybrid deployments and when using third-party antivirus?

In certain scenarios, emails are processed by a receive connector twice. One example is routing inbound emails from Microsoft Online to a third party for virus scanning. Afterwards, this third party sends the emails back to the original email recipient.

The issue arises from the fact that whitelisting is based on verifying the sender. When the email is redelivered by the antivirus provider, the sender has changed.

Adding the antivirus vendor to the whitelist is not the solution!

Instead, the receive connector must be configured to skip the most recent sender and check who originally sent the email (Enhanced Filtering for Connectors in Exchange Online). This allows whitelisting to take effect again.