-
In Cloud App Security, go to Policies. Under Global Settings > User-Defined Lists, choose Approved/Blocked Lists. Under Exchange Online, scroll down to the Approved Header Fields section.
Click the image to enlarge.
-
Enable the approved header field list for Exchange Online.
You can configure the list first and enable it later when you need to. -
Specify a header field name in the Name text box and a value for the field in the Value text box and select “Contains” or “Equals” as necessary.
"Equals" matches the exact header field value.
"Contains" matches any word or phrase in the header field value. -
Click Add.
The specified entry appears in the area below as the system automatically saves the configuration.
Click the image to enlarge.
When the specified header field of an email message contains or exactly matches the specified value depending on whether Contains or Equals is selected, the message will not be scanned by all enabled ATP and DLP policies for Exchange Online.
Be aware that Name and Value are case sensitive, and wildcard characters and regular expressions are not supported. The header field name and value cannot exceed 128 characters. -
Optionally add another header field as necessary.
The email message whose header field hits any of the specified entries will bypass policy scanning.
A maximum of 50 header fields is supported. - To delete a specified header field, click the trash can icon that corresponds to an entry.