How to Allow Legitimate Emails from a Partner Domain in Microsoft Defender for Office 365
Your organization has Microsoft Defender for Office 365. Users report that legitimate emails from a partner domain are being quarantined. You need to ensure these emails are delivered while maintaining security. What should you do?
Quick Answer
The correct answer is to add the partner domain to the Allow list in the Tenant Allow/Block List. This action directly instructs Microsoft Defender for Office 365 to override the filtering verdict for that specific domain, ensuring legitimate emails from the partner domain are delivered instead of being quarantined, while still maintaining security for other senders. On the MS-102 exam, this scenario tests your understanding of the Tenant Allow/Block List as a targeted override tool, with a common trap being the temptation to create a transport rule that bypasses all security checks or to disable anti-spam policies entirely, both of which are poor practices. Remember that the Allow list is a temporary fix; the long-term best practice is to fix the partner’s email authentication (SPF, DKIM, DMARC) to prevent future quarantining. Memory tip: Think “Allow list for the partner, not a blanket bypass”—it’s a scalpel, not a sledgehammer.
⚠ Common exam trap
MS-102 often tests the misconception that a mail flow rule (transport rule) is the best way to bypass spam filtering, when in fact the Tenant Allow/Block List is the recommended, granular, and auditable method for allowing specific senders or domains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the partner domain to the Allow list in the Tenant Allow/Block List.
The Tenant Allow/Block List in Microsoft Defender for Office 365 is the supported, granular mechanism for allowing specific senders or domains that are being incorrectly quarantined. Adding the partner domain as an allow entry tells Exchange Online Protection (EOP) to skip filtering actions (quarantine, junk, etc.) for messages from that domain while still applying other protections like malware scanning and Safe Links. This preserves security posture because only the specific false-positive source is exempted, not the entire filtering pipeline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add the partner domain to the Allow list in the Tenant Allow/Block List.
Why this is correct
Adding the partner domain to the Tenant Allow/Block List overrides the quarantine verdict for that sender, satisfying the requirement that legitimate partner mail be delivered. Entries here take precedence over filtering verdicts, so messages bypass quarantine while spoofing and malware protection remain active for all other senders.
- ✗
Disable spam filtering for the partner domain.
Why it's wrong here
Disabling spam filtering removes all protection for that domain, allowing genuinely malicious mail through, rather than permitting only the legitimate partner traffic. Turning filtering off entirely suits a trusted internal relay where no external mail is received.
- ✗
Lower the spam confidence level (SCL) threshold for the organization.
Why it's wrong here
Lowering the organisation-wide SCL threshold changes sensitivity for all senders, letting more spam into every mailbox instead of addressing the partner domain specifically. Adjusting SCL globally suits tuning overall filtering strictness, not exempting one trusted partner.
- ✗
Create a mail flow rule to bypass spam filtering for the partner domain.
Why it's wrong here
A bypass rule skips spam filtering for the whole domain, so spoofed or compromised partner mail also reaches inboxes, weakening security rather than maintaining it. Bypass rules suit trusted sources where filtering causes false positives and risk is accepted.
Go deeper
Related to this question
Learn chapter
Exchange Online Administration
Key term
Security posture
An organization's overall cybersecurity strength, including policies, controls, and readiness to defend against and respond to threats.
Key term
Safe Links
Safe Links is a Microsoft Defender for Office 365 feature that scans URLs in emails and documents in real time to protect users from malicious websites.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Defender for Office 365. Users report that legitimate emails from a specific partner domain are being moved to Junk Email folder. You verify that the partner's SPF, DKIM, and DMARC records are correctly configured. Which two actions should you take to resolve this issue?
medium- A.Modify the Anti-Spam policy to increase the spam threshold.
- ✓ B.Review the Anti-Phishing policy's spoof intelligence settings.
- C.Configure the Outbound spam filter policy.
- D.Disable the Spam filter for the affected users.
- ✓ E.Add the partner domain to the Tenant Allow/Block List as an allowed domain.
Why B: Legitimate emails from a partner domain are being moved to Junk Email folder despite correct SPF, DKIM, and DMARC records. This typically indicates that the emails are being misclassified as spoofed or phishing. Reviewing the Anti-Phishing policy's spoof intelligence settings (Option B) allows you to check if the partner domain is being incorrectly treated as a spoof sender and adjust the settings accordingly. Additionally, adding the partner domain to the Tenant Allow/Block List as an allowed domain (Option E) explicitly permits emails from that domain, overriding any false positive filtering. Option A (increasing spam threshold) may reduce spam filtering effectiveness and does not address the root cause. Option C (Outbound spam filter policy) affects outgoing emails, not inbound. Option D (disabling spam filter) is too aggressive and removes protection for the affected users. Therefore, the correct actions are B and E.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.