Get All AIP encrypted files - SharePoint Online

One of the recent project merger and acquisition.  Technology - M365 tenant to Tenant migration Areas of consolidation 1. Mailboxes  2. SharePoint online data 3. OneDrive for Business data 4. Teams data migration 5. Security and Compliance Migration  Area of concern from security and compliance side was the encrypted files within EXO, SPO, Teams, ODB. Issue with encrypted data migration - end users will not be able to access the documents once the Source tenant is decommissioned.   Solution available -  Ask end users to unencrypt the data before migration  Alternet Solution - 1. Decrypt the files, mails using eDiscovery - This will give us output in PST format will is available for offline access, but the data in source will still be encrypted.  Decryption in eDiscovery - Microsoft Purview (compliance) | Microsoft Docs   2. Use Get-AIPfileLabel and Get-AIPFileLabel but in order to use this you must be aware of all the files paths.  Challenges -  1. We do not want end user intervention

Analyze Office 365 Message headers

How to get the message headers?

From outlook.

i. Double click on the mail “This will open the mail in new window”

ii. Go to File option in the tool bar.

iii. File > Info > Properties

In the new pop up window copy all the contents available under “Internet Header” option.



From OWA

a. Open the mail

b. Click on dropdown option available under “reply all” option

c. Under the dropdown options select “Message Properties”.




·         Summary will give the overview of the mail like
o   Subject
o   From , To , …etc
·         Received header will give the over view of how the mail traveled.



****The Above Picture represents a Sample for demonstration only.

FT - Frontend Transport
MB – Mailbox server
CA – CAS mailbox
EOP – Exchange Online Protection
HT – Quarantine

 
·         Forefront Antispam Report Header – This section represents
o   Country of mail origin
o   Spam confidence level
o   Connecting IP – senders Public facing server IP details, used to communicate with our mail server.
o   Spam Filtering Verdict

·         Microsoft Antispam Header - This section represents.
o   Bulk confidence level
o   Phishing confidence level

·         Other Headers – This will give you the all details of the message.

we need to check “X-Forefront-Antispam-Report” and “X-Microsoft-Antispam” under this section to understand why the mail was marked as spam or not marked as spam.

X-Forefront-Antispam-Report – This section helps us to understand why our mail was classified/marked as spam or Not a Spam.

We have to check these values under this section.

CIP
IPV
EFV
SFV

Please refer to this link for the details of the values specifies for SFV and SCL.

X-Microsoft-Antispam –  This will help us to identify if the mail was sent to bulk users and it is a Phishing mail.


We get the following information under this option

BCL
PCL

Please refer to this link for the details of the values specifies for SFV and SCL.




Comments

Popular posts from this blog

Error - AttributeValueMustBeUnique in Azure AD connect sync

Error - QuarantinedAttributeValueMustBeUnique

Add members to office 365 Security Group Using PowerShell and CSV

Enforce MFA using CSV