Feedback by UserVoice

Office 365 Security & Compliance

We have partnered with UserVoice, a third-party service and your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy. Please do not send any novel or patentable ideas, copyrighted materials, samples or demos for which you do not want to grant a license to Microsoft.

Welcome to the Security (Protection) & Compliance UserVoice forum. We’re happy you’re here! If you have suggestions or ideas on how to improve Security or Compliance related features in O365, we’d love to hear them!

How it works
◾Check out the ideas others have suggested and vote on your favorites
◾If you have a suggestion that’s not listed yet, submit your own — 25 words or less, please
◾Include one suggestion per post

Thanks for joining our community and helping improve these features in Office 365!

Need Tech Support? Please see the O365 Community for the product or feature you are having issues with, or open a support ticket through your Office 365 administrator portal.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Allow more historical audit log data to be retrieved with the Management API

    I used to use Powershell to download data from the Unified Audit log (see https://docs.microsoft.com/en-us/office365/securitycompliance/search-the-audit-log-in-security-and-compliance). Powershell allowed me to access audit events up to 3 months old.

    I have started to replace Powershell with the Office 365 management API, but I can only go back 7 days with the API. Please give the official API the same data access as Powershell,

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Auditing  ·  Flag idea as inappropriate…  ·  Admin →
  2. Intune Policy based deployment

    Policy based deployment which at least encompasses capability to automate deployment of updates. e.g. Granular calendar based control to deploy say deploy all security updates to these specific groups on 21st of every month etc. You may want to use the new Azure AD dynamic grouping, at this time I know nothing about this as it's not rolled out yet.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Malware  ·  Flag idea as inappropriate…  ·  Admin →
  3. I had a great support from Office 365 Security team this week. I was constantly attack via phone.

    I had a great Support from the German SecurityTeam of Office 356 this week (Mr Demtschenko). He made great efforts to help the attacks I was getting by phone and investigatet that the number that called me was suspicous, plus, the method they used (looking up one´s Computer ID) was faked by telling me some number that is installed in all Computers with Micrososft installed. A good advice to prevent such Information is eventually to inform customers ahead, in what cases one should be suspicious to fraud or phishing as for instance, calls from "Microsoft Headquarter".

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  4. Advanced Threat Protection Wrongly processing all tenant users with the same domain

    If when creating a rule for Safe attachments or safe links domains are selected instead of individual users, everyone in that domain gets the ATP service regardless of subscription. It is great to have multiple rulers when you want to apply different rules to different users, It is a burden to have to enter and maintain these lists when the rule applies to all users with the ATP subscription.

    Request is to put an additional logic in the tool when domain is selected to check if the user has the ATP subscription before applying the rule and ATP process.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  5. Support for multi-values in Asset ID in event-driven retention

    When using event-driven retention, users apply a label (that's tied to an event type) and an Asset ID to documents. I believe right now only a single value can be entered into Asset ID. Is there any plans to support multiple Asset ID's (i.e. make Asset ID a multi-value field)?

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  6. Please can you add pdf's to the encrytion of documents.

    Please can you add pdf's to the encrytion of documents. We have all of our application forms as pdf's and want to send them securely to our clients. But at the moment only office related products work and not pdf's.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Message Encryption & Rights Management  ·  Flag idea as inappropriate…  ·  Admin →
  7. Stop blocking legitimate links from Entertainment Weekly newsletters.

    Stop blocking legitimate links from Entertainment Weekly newsletters.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  8. Add periodic Snapshots of Exchange Online to allow restore of active mailboxes

    Currently there's no way to restore the entire active mailbox from a specific time. Please add this feature.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  eDiscovery  ·  Flag idea as inappropriate…  ·  Admin →
  9. My User Compliance Score fell from 41 to 29, but i cant see a reason why it did

    My User Compliance Score fell from 41 to 29, but i cant see a reason why it did, I discussed with Microsoft backend, tech lead, they said they cant tell me why my score fell
    Its like my credit score fell and I cant find out which credit card I missed payment on,,thats not acceptable

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Compliance Manager  ·  Flag idea as inappropriate…  ·  Admin →
  10. Remove references to the 'OME Viewer' app from encrypted messages

    Although the OME Viewer app was pulled from phone app stores on Aug 15, 2018, the secure e-mail displays "If you don't have the OME Viewer app, [download it now] (link)" on some devices.
    Please remove this message.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Message Encryption & Rights Management  ·  Flag idea as inappropriate…  ·  Admin →
  11. Unique permission does not work on Lists when a user is added instead of adding a group

    If a user is added with contribute permission after breaking permission of a list, it cannot make any changes in the list and gets an error that "unable to communicate with server" . But if the user is added through a share point groups it works fine. And if you try the same on a library the user can upload and create new documents even when added directly.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  12. ATP WhiteList Email Origin through automated URL Intelligence w/ CAPTCHA

    [9:46 AM] Justin Robbins
    So lets add this to ATP: White List Only option
    ​[9:47 AM] Justin Robbins
    You send an email to the recipient. It gets held in quarantine. ATP Replies (if it's enabled for the mailbox) with - a portal LINK, to verify the sender is an actual person. They fill out their name and email address. Then they get white listed to the end user
    ​[9:48 AM] Justin Robbins
    The email gets released to the end user. Future emails, will go through from that address. If the senders email address or sending server changes, ATP can reask…

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Spam & Phishing  ·  Flag idea as inappropriate…  ·  Admin →
  13. Get Best Idea and Decorations-Rihansh Wedding planner

    One of the best wedding planner in lucknow. Rihansheve N Planner is successfully planned and executed big and fat indian weddings in lucknow. Like destination wedding, theme wedding decor. They also provide birthday and kitty party services in lucknow. To know more services visit:- https://www.slideserve.com/Rihansheve/get-best-idea-and-decorations-rihansh-wedding-planner-powerpoint-ppt-presentation

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  eDiscovery  ·  Flag idea as inappropriate…  ·  Admin →
  14. Email links stopped working today. I'm not the first to report this conflict.

    Email links stopped working today. I'm not the first to report this conflict.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Advanced Security Management  ·  Flag idea as inappropriate…  ·  Admin →
  15. Better eDiscovery and Hold Processes for Large Groups of Users

    Would be nice to see more of a flag and continue when trying to run a Hold or eDiscovery process for a large group or amount of users where if one mailbox has a problem it does not cause the whole process to fail with a generic error that makes it impossible to troubleshoot. Would be better if the process ran and just flagged mailboxes that the process could not be completed for and just move on to the rest of the mailboxes instead of having the whole process fail. We have ran into this multiple times now and had…

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  eDiscovery  ·  Flag idea as inappropriate…  ·  Admin →
  16. Need to determine if a secure message is read and by who

    Determine if a secure message was read and by who for audit and forensic purposes. Opening secure emails requires a user to login or receive a onetime pass code to view the email. This event should be logged and reportable.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Message Encryption & Rights Management  ·  Flag idea as inappropriate…  ·  Admin →
  17. I don't even use office 365 and my outlook email links are also being blocked today as many others have discovered

    Whatever changed today is blocking all kinds of legitimate site from access links in email in outlook. For several weeks, I can't reply to an email from outlook. My work-around is to use MSN premium and then relys or forwards still work for now.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  18. Email and attachment encryption with a password in outlook

    I want to be able to send an email with attched files in a secured way. the recipient is supposed to enter just a password he once received to open and read the email and also the attched files.
    this should be an easy button to encrypt the email whenever you want, maybe even select email adresses out of the adress book to send always password protected emails for this recipient.
    just like the function of crypted.co
    an add in to outlook.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Message Encryption & Rights Management  ·  Flag idea as inappropriate…  ·  Admin →
  19. Security and Compliance does not log a complete audit of information

    Good Morning,

    Security and Compliance does not log a complete audit of information and generates a report in EXCEL where it does not show if the user has deleted a specific email message.
    Ridiculous not knowing that a user has deleted the correct sender's email message.
    As administrators will PROVE that user actually deleted that email.
    Microsoft should rethink the audit report for more concrete information.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Auditing  ·  Flag idea as inappropriate…  ·  Admin →
  20. quarantined emails to be deleted and show if they have been delivered.

    allow quarantined emails to be deleted and show if they have been delivered.

    1 vote
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Spam & Phishing  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base