Feedback by UserVoice

Office 365 Security & Compliance

We have partnered with UserVoice, a third-party service and your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy. Please do not send any novel or patentable ideas, copyrighted materials, samples or demos for which you do not want to grant a license to Microsoft.

Welcome to the Security (Protection) & Compliance UserVoice forum. We’re happy you’re here! If you have suggestions or ideas on how to improve Security or Compliance related features in O365, we’d love to hear them!

How it works
◾Check out the ideas others have suggested and vote on your favorites
◾If you have a suggestion that’s not listed yet, submit your own — 25 words or less, please
◾Include one suggestion per post

Thanks for joining our community and helping improve these features in Office 365!

Need Tech Support? Please see the O365 Community for the product or feature you are having issues with, or open a support ticket through your Office 365 administrator portal.

How can we improve compliance or protect your users better in Office 365?

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Separate area to BLOCK email addresses and domains (not allow it to get to the user, or use transport rule space)

    A block list (email addresses and/or domains)
    - which doesn't use up 8K of transport rule memory
    - which BLOCKS it (block should mean BLOCK). Blocking should NOT ALLOW IT TO GET TO THE USER (even if it's their Junk Mail).

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  DLP & Transport Rules  ·  Flag idea as inappropriate…  ·  Admin →
  2. Security-sensitive SMB forum (Drs, lawyers, finance, audit...). Community trust providers need security feature attention ASAP.

    Basic legal compliance needs shared by many important specialty community trust providers will not be served, if only votes are used to determine features.

    The best of high trust industry providers are of minority size (i.e., professional dr, lawyer, finance, audit, IT security firms). But, this minority serves the vast majority's sensitive needs (both consumer, commercial, and government) with fundamentally important trust at the core of their services.

    So if the majority wants secure bank/health/educational/location records - then supporting the shared needs of these high trust minority providers is key to helping solve bigger problems.

    For example, a simple process…

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  3. Hate UserVoice. Is limiting my ability to sign petitions on topics I care about!!

    Hate UserVoice. Is limiting my ability to sign petitions on topics I care about!!

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  4. Intune Policy based deployment

    Policy based deployment which at least encompasses capability to automate deployment of updates. e.g. Granular calendar based control to deploy say deploy all security updates to these specific groups on 21st of every month etc. You may want to use the new Azure AD dynamic grouping, at this time I know nothing about this as it's not rolled out yet.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Malware  ·  Flag idea as inappropriate…  ·  Admin →
  5. I had a great support from Office 365 Security team this week. I was constantly attack via phone.

    I had a great Support from the German SecurityTeam of Office 356 this week (Mr Demtschenko). He made great efforts to help the attacks I was getting by phone and investigatet that the number that called me was suspicous, plus, the method they used (looking up one´s Computer ID) was faked by telling me some number that is installed in all Computers with Micrososft installed. A good advice to prevent such Information is eventually to inform customers ahead, in what cases one should be suspicious to fraud or phishing as for instance, calls from "Microsoft Headquarter".

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  6. Attack simulator spear phishing template variables

    In the attack simulator to run a spear phishing attack, the template variables are only username and URL. Adding another variable for email address would be helpful in addition to these as email address is often the user ID for many accounts, so being able to display the email address in the template would further simulate true attacks.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  7. Advanced Threat Protection Wrongly processing all tenant users with the same domain

    If when creating a rule for Safe attachments or safe links domains are selected instead of individual users, everyone in that domain gets the ATP service regardless of subscription. It is great to have multiple rulers when you want to apply different rules to different users, It is a burden to have to enter and maintain these lists when the rule applies to all users with the ATP subscription.

    Request is to put an additional logic in the tool when domain is selected to check if the user has the ATP subscription before applying the rule and ATP process.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  8. Support for multi-values in Asset ID in event-driven retention

    When using event-driven retention, users apply a label (that's tied to an event type) and an Asset ID to documents. I believe right now only a single value can be entered into Asset ID. Is there any plans to support multiple Asset ID's (i.e. make Asset ID a multi-value field)?

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  9. Make application password easy to remember and not computer generated.

    When 2FA and application password is enabled it replaces "normal" password with computer generated one. That string of random characters is impossible to remember by humans and this is bad.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  10. Please can you add pdf's to the encrytion of documents.

    Please can you add pdf's to the encrytion of documents. We have all of our application forms as pdf's and want to send them securely to our clients. But at the moment only office related products work and not pdf's.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  11. Add periodic Snapshots of Exchange Online to allow restore of active mailboxes

    Currently there's no way to restore the entire active mailbox from a specific time. Please add this feature.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  eDiscovery  ·  Flag idea as inappropriate…  ·  Admin →
  12. My User Compliance Score fell from 41 to 29, but i cant see a reason why it did

    My User Compliance Score fell from 41 to 29, but i cant see a reason why it did, I discussed with Microsoft backend, tech lead, they said they cant tell me why my score fell
    Its like my credit score fell and I cant find out which credit card I missed payment on,,thats not acceptable

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Compliance Manager  ·  Flag idea as inappropriate…  ·  Admin →
  13. Remove references to the 'OME Viewer' app from encrypted messages

    Although the OME Viewer app was pulled from phone app stores on Aug 15, 2018, the secure e-mail displays "If you don't have the OME Viewer app, [download it now] (link)" on some devices.
    Please remove this message.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  14. Unique permission does not work on Lists when a user is added instead of adding a group

    If a user is added with contribute permission after breaking permission of a list, it cannot make any changes in the list and gets an error that "unable to communicate with server" . But if the user is added through a share point groups it works fine. And if you try the same on a library the user can upload and create new documents even when added directly.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  15. Email links stopped working today. I'm not the first to report this conflict.

    Email links stopped working today. I'm not the first to report this conflict.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  16. Better eDiscovery and Hold Processes for Large Groups of Users

    Would be nice to see more of a flag and continue when trying to run a Hold or eDiscovery process for a large group or amount of users where if one mailbox has a problem it does not cause the whole process to fail with a generic error that makes it impossible to troubleshoot. Would be better if the process ran and just flagged mailboxes that the process could not be completed for and just move on to the rest of the mailboxes instead of having the whole process fail. We have ran into this multiple times now and had…

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  eDiscovery  ·  Flag idea as inappropriate…  ·  Admin →
  17. I don't even use office 365 and my outlook email links are also being blocked today as many others have discovered

    Whatever changed today is blocking all kinds of legitimate site from access links in email in outlook. For several weeks, I can't reply to an email from outlook. My work-around is to use MSN premium and then relys or forwards still work for now.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  18. Email and attachment encryption with a password in outlook

    I want to be able to send an email with attched files in a secured way. the recipient is supposed to enter just a password he once received to open and read the email and also the attched files.
    this should be an easy button to encrypt the email whenever you want, maybe even select email adresses out of the adress book to send always password protected emails for this recipient.
    just like the function of crypted.co
    an add in to outlook.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  19. quarantined emails to be deleted and show if they have been delivered.

    allow quarantined emails to be deleted and show if they have been delivered.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Spam & Phishing  ·  Flag idea as inappropriate…  ·  Admin →
  20. Disable the new enhanced anti-spoof capability in Office 365 ATP

    Microsoft enhanced anti-spoof capabilities for Office 365. This new feature is responsible for automatic junking of a message if it fails implicit authentication. The limitation that now have is that we only can use policies to customize the actions and additionally block or allow specific senders based on their authentication status. Want to have have the ability to disable this (enhanced anti-spoofing) feature.

    1 vote
    Vote
    Sign in
    (thinking…)
    Password icon
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Spam & Phishing  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base