Shield Transport Rules

Description

Shield transport rules reside in the Shield organization's Microsoft 365 tenant. All rules are added during the Shield deployment process. 

Please ensure that all Shield updates are performed in order for Shield transport rules to stay current. If you have not performed all updates for the Shield organization the transport rules may look different. 

Do not replace existing transport rules with the rules below. Instead, run a full deployment via View Deployments to properly update the organization.

Corresponding Shield Connectors are detailed here.

Shield - Send to Frontline

Status

Enabled


Priority

0

Stop processing more rules: ✅ (Yes)


Conditions

Name

Shield - Send to Frontline

Apply this rule if:
The recipient → is a member of this group

The recipient is a member of:
[a value unique to your M365 tenant]


Do the following

Redirect the message to:
The following connector

Route the message using the following connector:
Shield - Send to Frontline


And

Modify the message properties:
Set a message header

Set the message header:
X-Frontline-API

To the value:
{"extract_origin": "true"}


Except if

The message headers:
Matches these text patterns

X-Shield-Relay-Token message header matches:
[a value unique to your M365 tenant]

Shield - Send to Frontline rule.png

Shield - Bypass Spam Filtering

Status

Enabled


Priority

1

Stop processing more rules: ❌ (No)


Conditions

Name

Shield - Bypass Spam Filtering

Apply this rule if:
The message headers → matches these text patterns

X-Shield-Relay-Token message header matches:
[a value unique to your M365 tenant]


Do the following

Modify the message properties:
Set the spam confidence level (SCL)

Set the spam confidence level (SCL) to:
-1


Except if

The message headers:
Matches these text patterns

X-Shield-API message header matches:
"action":"bypass" or "action":"junk"

Shield - Bypass Spam Filtering rule.png

Shield - Send to Bracket

Status

Enabled


Priority

2

Stop processing more rules: ✅ (Yes)


Conditions

Name

Shield - Send to Bracket

Apply this rule if

Condition 1

  • The recipientis external/internal
  • Recipient location:
    • 'NotInOrganization'

AND

Condition 2

  • The subject or bodysubject matches these text patterns
  • Pattern:

    ^\[.*\]

AND

Condition 3

  • The senderis external/internal
  • Sender location:
    • 'InOrganization'

Do the following

  • Redirect the message tothe following connector
  • Connector:
    • 'Shield - Send to Bracket'

Exceptions

  • None configured.

 

Shield - Send to Bracket rule.png


 

 


Shield - Send to Outpost

Status

Enabled

Priority

3

Stop processing more rules: ✅ (Yes)


Conditions

Name

Shield - Send to Outpost

Apply this rule if

Condition 1

  • The recipientis external/internal
  • Recipient location:
    • 'NotInOrganization'

AND

Condition 2

  • The senderis external/internal
  • Sender location:
    • 'InOrganization'

AND

Condition 3

  • The senderis a member of this group
  • Group: [a value unique to your M365 tenant]

Do the following

  • Redirect the message tothe following connector
  • Connector:
    • 'Shield - Send to Outpost'

Exceptions

  • None configured.
Shield - Send to Outpost rule.png

 


Shield - Send to Junk

Status

Enabled

Priority

4

Stop processing more rules: ❌ (No)


Conditions

Name

Shield - Send to Junk

Apply this rule if

Condition 1

  • The recipientis a member of this group
  • Group: [a value unique to your M365 tenant]

AND

Condition 2

  • The message headers...matches these text patterns
  • Header:
    • X-Shield-API
  • Pattern:

    "action":"junk"

Do the following

  • Modify the message propertiesset the spam confidence level (SCL)
  • SCL Value:
    • 6

Exceptions

  • None configured.
Shield - Send to Junk rule.png

Related to

Updated

Was this article helpful?

0 out of 0 found this helpful