4 - ユーザー管理の隔離と管理者の隔離
このチュートリアルでは、SPAMおよびSPOOFメッセージをユーザー管理の隔離に、MALICIOUSメッセージを管理者の隔離に配信する方法を学びます(これには、管理者がメールを解放する必要があります)。
You first need to configure the domains you are onboarding on the Email Security (formerly Area 1) dashboard. To configure your domains:
- Log in to the Email Security dashboard ↗.
- Go to Settings (the gear icon).
- Go to Email configuration > Domains & Routing > Domains.
- Make sure each domain you are onboarding has been added.
- For each domain you are configuring, select … > Edit, and set the following options:
- Domain -
<YOUR_DOMAIN>. - Configured as -
MX Records. - Forwarding to - This should match the expected MX record for each domain in your Office 365 account ↗.
- IP Restrictions - Leave this field empty.
- Outbound TLS -
Forward all messages over TLS. - Quarantine Policy - いかなる処分も確認しない。
- Domain -
To create quarantine policies:
-
Open the Microsoft 365 Defender console ↗.
-
Go to Email & collaboration > Policies & rules.
-
Select Threat policies.
-
Under Rules, select Quarantine policies.
-
Select Add custom policy.
-
Set the Policy name to
UserNotifyUserRelease. -
Select Next.
-
In Recipient message access, select Set specific access (Advanced), and then:
- In Select release action preference, choose Allow recipients to release a message from quarantine.
- In Select additional actions recipients can take on quarantined messages, select the Delete and Preview checkboxes.

-
Select Next.
-
In Quarantine notification, select Enable.
-
Select Next.
-
Review your settings and select Submit.
-
Select Done.
-
Select Add custom policy.
-
Set the Policy name to
UserNotifyAdminRelease. -
Select Next.
-
In Recipient message access, select Set specific access (Advanced), and then:
- In Select release action preference, from the drop-down menu, choose Allow recipients to request a message to be released from quarantine.
- In Select additional actions recipients can take on quarantined messages, select the Delete and Preview checkboxes.

-
Select Next.
-
In Quarantine notification, select Enable.
-
Select Next.
-
Review your settings and select Submit.
-
Select Done.
To configure quarantine notifications:
-
Open the Microsoft 365 Defender console ↗.
-
Go to Email & collaboration > Policies & rules.
-
Select Threat policies.
-
Under Rules, select Quarantine policies.
-
Select Global settings.
-
Scroll to the bottom and set the desired frequency in Send end-user spam notifications every (days). This value can only be incremented in days.

-
Select Save.
迷惑メール対策ポリシーを設定するには:
-
メールとコラボレーション > ポリシーとルールに移動します。
-
脅威ポリシーを選択します。
-
ポリシーの下で、迷惑メール対策を選択します。
-
**迷惑メール対策受信ポリシー(デフォルト)**のテキストを選択します(チェックボックスではありません)。
-
アクションセクションで、下にスクロールしてアクションの編集を選択します。

-
次の条件とアクションを設定します(見つけるために上下にスクロールする必要があるかもしれません):
- 迷惑メール: メッセージを隔離する。
- 隔離ポリシーを選択: UserNotifyUserRelease。
- 高信頼度の迷惑メール: メッセージを隔離する。
- 隔離ポリシーを選択: UserNotifyAdminRelease。
- フィッシング: メッセージを隔離する。
- 隔離ポリシーを選択: UserNotifyAdminRelease。
- 高信頼度のフィッシング: メッセージを隔離する。
- 隔離ポリシーを選択: UserNotifyAdminRelease。
- この日数だけ迷惑メールを隔離に保持する: デフォルトは15日です。メールセキュリティは15-30日を推奨します。

- 迷惑メール: メッセージを隔離する。
-
保存を選択します。
To create the transport rules that will send emails with certain dispositions to Email Security:
-
Open the new Exchange admin center ↗.
-
Go to Mail flow > Rules.
-
Select Add a Rule > Create a new rule.
-
Set the following rule conditions:
- Name: `Email Security User Quarantine Message`.
- Apply this rule if: The message headers > includes any of these words.
- Enter text:
X-Area1Security-Disposition> Save. - Enter words:
`UCE`, `SPOOF`> Add > Save.
- Enter text:
- Apply this rule if: Select + to add a second condition.
- And: The sender > IP address is in any of these ranges or exactly matches > enter the egress IPs in the Egress IPs page.
- Do the following - _メッセージのプロパティを変更_ > _スパム信頼度レベル (SCL) を設定_ > _5_.
-
Select Next.
-
You can use the default values on this screen. Select Next.
-
Review your settings and select Finish > Done.
-
Select the rule `Email Security User Quarantine Message` you have just created, and Enable.
-
Select Add a Rule > Create a new rule.
-
Set the following rule conditions:
- Name: `Email Security User Quarantine Message Admin Release`.
- Apply this rule if: The message headers > includes any of these words.
- Enter text:
X-Area1Security-Disposition> Save. - Enter words: `MALICIOUS` > Add > Save.
- Enter text:
- Apply this rule if: Select + to add a second condition.
- And: The sender > IP address is in any of these ranges or exactly matches > enter the egress IPs in the Egress IPs page.
- Do the following: _メッセージのプロパティを変更_ > _スパム信頼度レベル (SCL) を設定_ > _9_.
-
Select Next.
-
You can use the default values on this screen. Select Next.
-
Review your settings and select Finish > Done.
-
Select the rule `Email Security User Quarantine Message Admin Release` you have just created, and select Enable.