Microsoft has resolved a widespread issue with its Exchange Onlinethat caused legitimate emails from Gmail accounts to be incorrectly identified as spam and sent to quarantine.
See also: Microsoft re-releases Exchange Server security update

The issue, which began on April 25, affected many organizations using Microsoft 365 and was officially recorded with incident code EX1064599.
According to official statement , the issue was traced to a flawed machine learning (ML) model used in Exchange Online Protection (EOP), which incorrectly classified legitimate Gmail messages as "High Confidence Phish" with a spam confidence level (SCL) of 8. This classification resulted in the emails being automatically moved to quarantine, preventing them from reaching their intended recipients.
The most confusing aspect of the problem for administrators was its inconsistent behavior. Users reported cases where identical emails, sent to multiple recipients within the same organization, were delivered normally to some inboxes, while being moved to quarantine for others.
See also: Microsoft Outlook, Exchange and Teams face global blackout
This randomness significantly complicated the process of identifying and resolving the problem, creating confusion for IT administrators. Microsoft engineers addressed the issue by rolling back a previous version of the machine learning model.

In their final update, on May 1, Microsoft confirmed: "After a period of monitoring, we confirmed through the service's health telemetry tools that rolling back to the previous version of the machine learning model successfully fixed the issue."
During the six-day incident, system administrators were able to implement temporary workarounds to mitigate the problem. Microsoft suggested creating custom allow rules to ensure that messages from Gmail were not incorrectly labeled as spam.
See also: Microsoft Exchange: Warnings about emails exploiting spoofing vulnerability
Based on the above, this incident highlights the vulnerability of machine learning-based email filtering mechanisms, as well as the critical role of IT administrators in promptly addressing such malfunctions. The ability to configure security policies, such as custom whitelisting rules, proves to be vital in cases where automated models do not work as intended.
Source: cybersecuritynews
