Feedback by UserVoice

Office 365 Security & Compliance

We have partnered with UserVoice, a third-party service and your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy. Please do not send any novel or patentable ideas, copyrighted materials, samples or demos for which you do not want to grant a license to Microsoft.

Welcome to the Security (Protection) & Compliance UserVoice forum. We’re happy you’re here! If you have suggestions or ideas on how to improve Security or Compliance related features in O365, we’d love to hear them!

How it works
◾Check out the ideas others have suggested and vote on your favorites
◾If you have a suggestion that’s not listed yet, submit your own — 25 words or less, please
◾Include one suggestion per post

Thanks for joining our community and helping improve these features in Office 365!

Need Tech Support? Please see the O365 Community for the product or feature you are having issues with, or open a support ticket through your Office 365 administrator portal.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Disable download option at library in SharePoint

    At site permissions, by the permission levels option, I can't configure a level where the user just can read online the content of library and don't be able to download the content.That is to say, I can't disable or restrinct the download option even when:
    1. I assign a just read permission and/or
    2. I activate de IRM to the library. This option force to acquire a licensed and compatible software to read the PDF documments. Is not what our organization are looking for.

    This is a basic option that should be available, don't you think?

    256 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    9 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  2. Ability to disable or enable Office365 Mail Protection

    I am not a fan of mail protection or its administration in a Hybrid environment and would prefer to use a mail-filter device.
    This is especially a pain due to the fact that legitimate messages are being sent to the Junk E-Mail folder by mail protection.

    257 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    try this instead  ·  13 comments  ·  Spam & Phishing  ·  Flag idea as inappropriate…  ·  Admin →
  3. Give more detail on the TLS and Connector reports that are available in the Security and Compliance Centre

    Allow you to drill down and get more detail on the TLS report. For example, which domains are not using TLS, or which domains are only using TLS 1.0.

    246 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    21 comments  ·  Reports  ·  Flag idea as inappropriate…  ·  Admin →

    1. Click into “details”.
    2. Choose “connector report”.
    3. Choose “request report”.
    4. Answer the questions in the wizard, clicking “Next”, “Next”, and “Save”.
    5. Wait for the report to come to the email address specified. It will contain the following fields:
    message_id, direction, sender_address, recipient_address, connector_name, connector_type, tls_version, tls_cipher

    With the Message_Id value, you can combine this with MessageTrace to get the Subject.

    If this does not help, please provide more information as to the scenario and detail that is missing. Thank you for the feedback!

  4. Make it possible to search subject in Message trace

    Can we have a feature in message trace of Admin center to allow us search email by their subjects

    247 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    14 comments  ·  Message Trace  ·  Flag idea as inappropriate…  ·  Admin →
  5. Allow Exchange Admin Auditing retention to be increased past 90 days

    The commands Set-AdminAuditLogConfig -AdminAuditLogAgeLimit do not work on 365. We have a requirement to keep all admin logs for 3 years but this cannot be performed.

    242 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    16 comments  ·  Auditing  ·  Flag idea as inappropriate…  ·  Admin →

    At this point, the Office 365 service only allows for the retention of audit entries for 90 days. Can you provide us more information regarding your requirement to keep logs for 3 years. Is this a legal obligation? Please provide details around the specific audit entries you would like to retain for an extended period of time.

  6. Add a "Trust this Device" option to reduce frequency of multi-factor prompt

    Most multi-factor/ 2-factor authentication schemes allow the user to check a box when they login using the second factor of authentication to say "Trust this Device", meaning "Don't ask for the second-factor code again on this device (optionally: for X days)". [Google, LastPass, Yahoo, ...]

    Microsoft Office 365 does not have this, which makes good login security unnecessarily burdensome, as the user must have their second factor authentication device with them at all times and use it every time they login.

    Some users will refuse to use it at all, given the extra burden. Others will use it but be…

    227 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    7 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  7. Increase Message Trace Limits

    Increase Message Trace limits from 5000 and 3000 (for detailed traces). Either increase the limits by default or allow a certain number of traces that include larger numbers of messages.

    Certain organizations rely heavily on running message traces for all of their messages.

    It is a requirement for our client to be able to trace all of their messages with detailed information and it's a clumsy solution to have to create a trace for every day out of the past 90 days (which they must do because they send and receive more than 3000 messages within a couple of days).

    223 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    13 comments  ·  Message Trace  ·  Flag idea as inappropriate…  ·  Admin →
  8. Allow deletion of "Other Suggestions" entries in Outlook

    The "Other Suggestions" list that pops up when you type an email address in the To: field in Outlook can quickly become cluttered with outdated and inaccurate entries. There is currently no easy way to delete these suggestions.

    Please provide a way to delete these entries one by one as you do with the "Recent People" autocomplete list (Del key or X button on right hand side) as well as a way to clear all entries.

    222 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    4 comments  ·  Flag idea as inappropriate…  ·  Admin →
  9. Add 3rd party Authenticator support to Office 365 2-factor auth

    Please add support for 3rd party 2-factor authenticator apps like LastPass Authenticator or Google Authenticator by adding support for RFC 6238 "TOTP: Time-Based One-Time Password Algorithm".

    I don't want to fill my phone with vendor-specific authenticator apps.

    https://en.wikipedia.org/wiki/Time-basedOne-timePassword_Algorithm

    224 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    14 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  10. Reduce unnecessary nested includes in your SPF record, to improve DNS efficiency

    If you run a service which might be responsible for sending mails on behalf of a customer, and consequently have an SPF record they need to "include:" in their own, I think that you should probably review it and see if you have an excessive number of DNS lookups in your SPF record.

    The problem is that if a customer of more than one of these mail service providers, and they have multiple include elements in their SPF record, it’s all too easy to breach the 10 DNS lookup limit, which could lead to random email loss (recipient MTAs giving…

    229 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    7 comments  ·  Spam & Phishing  ·  Flag idea as inappropriate…  ·  Admin →
  11. Advanced Threat Protection (ATP) Whilelist - add wildcard support and/or extend the 320 character limit

    Advanced Threat Protection (ATP) Safe Links whitelist currently has a 320 character limit, and does not allow wildecards.

    Please either turn on wildcards for the urls or expand the 320 character limit to something much larger.

    218 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    14 comments  ·  Malware  ·  Flag idea as inappropriate…  ·  Admin →
  12. Provide the ability to edit the default protection alert(s) in powershell

    First off the help for new-protectionalert -examples should provide more information than "insert example commands for example 1"

    Secondly, it does not appear to be possible to edit the default protectionalerts that exist on a new tenant in powershell.

    Attempting to get and then set the recipient crashes the powershell as follows.

    get-protectionalert | ? {$_.operation -eq 'MailRedirect'} | set-protectionalert -notifyuser noc@nocdomain.com
    WARNING: An unexpected error has occurred and a Watson dump is being generated: There is no rule matching identity
    'f00ed340-8f84-4eb4-83f3-0075a22b262e\Creation of forwarding/redirect rule'.
    There is no rule matching identity 'f00ed340-8f84-4eb4-83f3-0075a22b262e\Creation of forwarding/redirect rule'.

    + CategoryInfo          : NotSpecified: (:)
    220 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    12 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  13. Certificate of Destruction

    When applying the new unified retention policies across Office 365, and you have configured the policy to delete content after a specified period of time, is there any provisions for a review/approval process and/or a 'certificate of destruction' as an audit of what was deleted? This is a standard requirement for many Information Management teams as Courts of law look for prior review and approval for disposed content if called upon.

    207 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    5 comments  ·  Flag idea as inappropriate…  ·  Admin →
  14. Admin Notifications for Zero Hour Auto Purge (ZAP) actions.

    Need to have notification to Admins when ZAP takes an action on email.
    1) Need to know what was found and deleted
    2) Even more importantly, need to know what was found and WAS NOT deleted since it had already been read.

    208 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    8 comments  ·  Malware  ·  Flag idea as inappropriate…  ·  Admin →
  15. Microsoft Authenticator needs to display the machine / device name, application and location

    When Microsoft Authenticator pops up on your phone there is no indication of what device is requesting the authentication. It would be much better if the machine or device name, application and location was shown so that you know you are verifying a request that you have made

    206 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    5 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  16. Allow dynamic retention policy based on group membership

    The below is too great a restriction and renders the retention policy useless.

    Groups selection confirmation

    The specified groups will be expanded so that an In-Place Hold can be put on the mailboxes in these groups. Only the mailboxes that are currently members of these groups will be placed on hold. Mailboxes added to or removed from these groups won't be added or removed from this hold. After setting the group for the location, the new member changes for this group will not auto apply to this location settings. Do you want to expand these groups?

    215 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  17. Let admin view "Message Header" Details through admin portal.

    Let admin view Message Header Details through admin portal. Its very helpful if this feature will be added.

    204 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    5 comments  ·  Message Trace  ·  Flag idea as inappropriate…  ·  Admin →
  18. Compliance admins should be able to delete labels marked as record

    Under Classifications, a label created and marked as Record cannot be later changed or, more importantly, deleted by any administrator. As an admin can remove a document from bearing the status of record, they should therefore be able to delete a label with Record status. The combination of Record and Delete after 'x' years is very dangerous - not to mention a department may update their requirements in time.

    202 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  19. Advanced Threat Protection - SafeLinks - Create Submission Mechanism for False Positive Malicious Domains

    Advanced Threat Protection - SafeLinks - Create Submission Mechanism for False Positive Malicious Domains

    This idea would create a feedback / reporting mechanism for domains incorrectly tagged as malicious by the SafeLinks feature. We had an example of a partner domain that was tagged as malicious, had zero malware / good reputation / etc. (confirmed by Microsoft Support), and had no way to feed that information back into Microsoft for a review of the malicious domain list so it could be removed. Similar feedback mechanisms exist for false positive Spam and virus detections - URLs deserve the same treatment.

    200 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    10 comments  ·  Malware  ·  Flag idea as inappropriate…  ·  Admin →
  20. Allow powershell scripting in Advanced eDiscovery

    I have scripted out the entire eDiscovery process in E3 eDiscovery which allowed us to save time and money, and repeat searches with minor variations very easily. With Advanced eDiscovery, I am unable to do so. Please add powershell scripting support (or provide the documentation) so we can streamline our collection and export processes.

    198 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    working on it  ·  2 comments  ·  eDiscovery  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base