Get All AIP encrypted files - SharePoint Online

One of the recent project merger and acquisition.  Technology - M365 tenant to Tenant migration Areas of consolidation 1. Mailboxes  2. SharePoint online data 3. OneDrive for Business data 4. Teams data migration 5. Security and Compliance Migration  Area of concern from security and compliance side was the encrypted files within EXO, SPO, Teams, ODB. Issue with encrypted data migration - end users will not be able to access the documents once the Source tenant is decommissioned.   Solution available -  Ask end users to unencrypt the data before migration  Alternet Solution - 1. Decrypt the files, mails using eDiscovery - This will give us output in PST format will is available for offline access, but the data in source will still be encrypted.  Decryption in eDiscovery - Microsoft Purview (compliance) | Microsoft Docs   2. Use Get-AIPfileLabel and Get-AIPFileLabel but in order to use this you must be aware of all the files paths.  Challenges -  1. We do not want end user intervention

Advance Threat protection - Safe Attachment

While Showcasing the ATP features to a client in a POC i noticed the following.

ATP - Safe Attachment rule is set as Replace - Block bad attachment and continue to deliver the mail. However the Mail is not delivered it is deleted completely.



Solution 


Go to Exchange Admin Center > Protection > Malware Filter





By default the Malware Policy is set to delete the entire mail if something is found as malware in the mail or attachment.


Edit your Default policy.


1. Change the Default Setting to - Delete attachment and use default alert text or Custom Alert "depending on your requirement. In my case i had kept as default alert text.



2. You can also customize the Notification too. 
3. You can also set the settings so that it will notifies the sender and sender for the undelivered of the Mail.



4. A notification about the same can be sent to the Admins too, you can use default or costume alert type too. (This will send a intimation to the admin that a user"XXX" had been sent a Bad mail. 

Sample - notification mail to Admin.




After Making the changes i had sent a test mail and it was delivered with a notification. The Attachment was removed but the mail contents were as it is.

1. First did a message trace.





 2. Checked the recipient inbox. The mail was delivered without the attachment, instead there was a text file attached with the information that the attachment was removed as it was marked as Malware.




  










Comments

Popular posts from this blog

Error - AttributeValueMustBeUnique in Azure AD connect sync

Error - QuarantinedAttributeValueMustBeUnique

Add members to office 365 Security Group Using PowerShell and CSV

Enforce MFA using CSV

Analyze Office 365 Message headers