Phishing Confidence

George Zerphey 176 Reputation points
2025-01-02T19:51:13.72+00:00

We are considering increasing the phishing threshold within Defender for Office Anti-Phishing policies, but we want to get a good understanding of how many emails this will effect when we do. I tried looking at the EmailEvents table within defender to see how many had a phishing confidence of medium, but it appears those readouts are now limited to "Normal" and "High".

Is there any way to get a more granular breakdown of phishing confidence levels for emails so we can better understand the effect of have a more strict phishing policy?

Thank you,

Microsoft Exchange
Microsoft Exchange
Microsoft messaging and collaboration software.
620 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,460 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
232 questions
0 comments No comments
{count} votes

Accepted answer
  1. Xintao Qiao-MSFT 5,630 Reputation points Microsoft Vendor
    2025-01-03T06:18:07.18+00:00

    Hi, @George Zerphey

    Unfortunately, Exchange Online environments are not currently able to see PCL scores with refined scores, and the focus has shifted more to phishing threshold levels.

    In order to implement a more stringent phishing policy, you can try the following suggestions:

    1.If your email platform supports custom filtering rules, you can fine-tune these settings to adjust the sensitivity of your phishing filters. This may include setting different thresholds for various phishing indicators.

    2.Conduct regular audits and phishing simulation tests within your organization. This helps to evaluate the effectiveness of your phishing strategy and to understand the level of confidence in catching real threats.

    3.Encourage users to report suspicious phishing emails. The data reported by these users can then be analyzed to see how often they are correctly identified at different confidence levels.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.