Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC822720

Microsoft Defender for Office 365: Four override alerts retire in August 2024

Plan for Change
Major Change

Message ID

MC822720
View in Admin Center

Services

Exchange Online

Summary

Four legacy override alerts in Microsoft Defender for Office 365 will be retired in September 2024 due to redundancy from the Secure by default feature. Affected users with specific subscriptions will not need to take any action as this change will occur automatically.

Details

Updated August 28, 2024: We have updated the rollout timeline and content below. Thank you for your patience.

Microsoft Defender for Office 365 is retiring four legacy override alerts that are now mostly redundant due to Secure by default. With Secure by default, ZAP (zero-hour auto purge) blocks high confidence phishing emails by default despite the legacy overrides. The four alerts are:

  1. Phish not zapped because ZAP is disabled
  2. Malware not zapped because ZAP is disabled
  3. Phish delivered due to ETR override
  4. Phish delivered due to IP allow

As part of the deprecation and rollout,

  • These policies will no longer be part of the Alert policies in the Microsoft Defender portal.
  • Existing alerts that are already generated will be in the system (part of Alerts) until data retention applies.
  • Any features like AIR built on these policies will not function (return no data) but will not result in any crashes or issues to the system.
  • Any features like Investigations or post-breach functionalities will not have these alerts as part of the selection, filtering, or processing.

When is the change?

We plan to turn off these alerts starting August 18, 2024 and ending September 15, 2024.

Who is impacted?

  1. Phish not zapped because ZAP is disabled: E5/G5 or Microsoft Defender for Office 365 P2 add-on subscription
  2. Malware not zapped because ZAP is disabled: E5/G5 or Defender for Office 365 P2 add-on subscription
  3. Phish delivered due to ETR override: E1/F1/G1, E3/F3/G3, or E5/G5
  4. Phish delivered due to IP allow: E1/F1/G1, E3/F3/G3, or E5/G5

What should I do if I am impacted?

This change will happen automatically by the specified date. No admin action is required. Since these alerts are mostly redundant, we do not expect any impact. Defender XDR Customers using Defender for O365 as a secondary filter (MX record pointed to 3rd party service) and still want the alerts can create a custom detection rule on EmailEvents table with filters on OrgLevelAction & OrgLevelPolicy.

Timeline

📅
Published
Jul 19, 2024
Message published to Message Center
✏️
Updated
Aug 30, 2024
Message content updated
🏁
End Date
Oct 31, 2024
Message timeline ends

Tags

#Updated message#User impact#Admin impact#Retirement

Category

📋Plan for Change

Related Messages

Similar updates

MC801980●

Legacy Outlook clients retirement plan

Jun 14, 2024
MC786329●

Exchange Online to retire Basic Auth for Client Submission (SMTP AUTH)

Apr 26, 2024
MC1130607●

Outlook Web Access and new Outlook: ‘Mobile devices’ settings page to be removed

Aug 7, 2025
MC835648●

Announcing IPv6 Enablement for Accepted Domains

Jul 25, 2024
MC810420●

New Microsoft Outlook for Windows is GA on August 1, 2024

Jul 11, 2024