IP Allow Lists SHOULD NOT be Implemented
Last updated
Last updated
Microsoft Defender supports the creations of IP “allow lists,” which are intended to ensure that emails from specific senders are not blocked. However, as a result, emails from these senders bypass important security mechanisms, such as spam filtering, SPF, DKIM, DMARC, and FROM address enforcement.
IP “block lists” ensure that mail from these IP addresses is always blocked. Although we have no specific guidance on which IP addresses to add, block lists can be used to block mail from known spammers. The IP “safe lists” group is a dynamic list of “known, good senders,” which Microsoft sources from various third-party subscriptions. As with senders in the allow list, emails from these senders bypass important security mechanisms.
IP allow lists SHOULD NOT be created.
Safe lists SHOULD NOT be enabled.
A connection filter MAY be implemented to create an IP “block list.”
• Exchange Online Protection
To modify the connection filters, follow the instructions found on Use the Microsoft 365 Defender portal to modify the default connection filter policy.
Sign in to Microsoft 365 Defender.
Under Email & collaboration, select Policies & rules.
Under Policies, select Anti-spam.
Select Connection filter policy (Default).
Click Edit connection filter policy.
Ensure no addresses are specified under Always allow messages from the following IP addresses or address range.
Enter addresses under Always block messages from the following IP addresses or address range as needed.
Ensure Turn on safe list is not selected.
With this setting in place, there may be some false positives from IP addresses that are seen as malicious.