Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC794542

Microsoft Defender for Office 365: Tenant Allow/Block List will support blocking top-level domains and subdomains

Informational

Message ID

MC794542
View in Admin Center

Roadmap ID

389853
View in Roadmap

Services

Exchange Online
Microsoft Defender XDR

Affected Platforms

Web

Summary

Microsoft Defender for Office 365 will soon allow blocking of top-level domains and subdomains via the Tenant Allow/Block List, rolling out from late May to late June. This update applies to customers with Microsoft Exchange Online Protection and Microsoft Defender for Office 365 Plan 1 or Plan 2. No admin action is required before the rollout.

Details

Updated May 31, 2024: We have updated the content below with links to additional information. Thank you for your patience.

This message applies to customers with Microsoft Exchange Online Protection and Microsoft Defender for Office 365 Plan 1 or Plan 2.

Soon, you will be able to block sender emails based on their top-level domain by creating block entries in the Tenant Allow/Block List in Microsoft Defender XDR.

This message is associated with Microsoft 365 Roadmap ID 389853.

When this will happen:

This change will start rolling out in late May 2024 and should be completed by late June 2024.

How this will affect your organization:

Before the rollout: You are unable to block incoming emails from sender email addresses by blocking top level domains or subdomains in the Tenant Allow/Block List. 

After this rollout, you will be able to create entries in the Tenant Allow/Block List (via the Microsoft XDR portal or the PowerShell), using the format *.<TLD>, where <TLD> can be any top-level domain such as .net, .biz, .io, .movie, country codes like .in, .us, .ru, and so on. Entries will not be case sensitive and can be uppercase, lowercase, or mixed case.

The top-level domain entries will block all emails received from or sent to any email address or subdomain related to *.<TLD> during mail flow. Inbound emails will be quarantined like other blocked domains and addresses, and outbound emails will be rejected with non-delivery receipt clearly indicating the reason.

This rollout also provides support for subdomain blocking. You can create entries in the following format for subdomains *.SD1.TLD, *.SD2.SD1.TLD, *.SD3.SD2.SD1.TLD, and similar patterns.

This rollout will not affect your existing Tenant Allow/Block List entries.

What you need to do to prepare:

This rollout will happen automatically by the specified dates with no admin action required before the rollout. Your existing Tenant Allow/Block List entries as it won't be affected.

Additional information: Allow or block email using the Tenant Allow/Block List 

Timeline

📅
Published
May 20, 2024
Message published to Message Center
✏️
Updated
May 31, 2024
Message content updated
🏁
End Date
Aug 20, 2024
Message timeline ends

Tags

#Updated message#New feature#Admin impact

Category

📖Stay Informed

Related Messages

Similar updates

MC765804

Microsoft Defender for Office 365: Adding last used dates to Tenant Allow/Block Lists

Apr 2, 2024
MC889519

Microsoft Defender for Office 365: Tenant Allow/Block List will support IPv6 allow and block entries

Sep 13, 2024
MC799276

Microsoft Defender XDR: Simplified DomainKeys Identified Mail (DKIM) setup for enhanced domain protection

Jun 6, 2024
MC794813

Microsoft Defender for Office 365: Tenant Allow/Block Lists will support entry removal 45 days after last used date

May 21, 2024
MC790242

Microsoft Defender for Office 365: Reported mailbox notifications messages subject change

May 4, 2024