Overview
Trustifi's Threat Response system allows you to scan emails that already exist in your users' mailboxes, locate emails according to specific indicators, and perform different actions on emails that match your search criteria.
Requirements
Before performing a Threat Response action, ensure the following prerequisites are met:
1. Microsoft Exchange Integration
Your Trustifi plan must be integrated with your Exchange server
To enable: Navigate to the Inbound Integrations page (Inbound Management > Plan Settings > Integrations) and click on “Microsoft Exchange”
2. Office 365 Mailboxes
The mailbox(es) you want to scan must be connected to Office 365
3. Protected Mailboxes
The mailbox(es) must be "Protected" by Trustifi
To verify: Navigate to the Mailbox Management page (Inbound Management > Mailbox Management) and check the protection status column (displays "Protected" or "Exposed")
When To Use
Remove Recent Threats
Remove any threat or suspicious email that may have recently found its way to your users' inboxes
Post-Connection Cleanup
For organizations that have just connected to Trustifi's inbound security, Threat Response can perform a general scan of existing user mailboxes to find various malicious content or spam
Emerging Threat Detection
If information about a new type of malware or phishing attack has surfaced, Threat Response can be used to check if any existing emails contain this type of threat
Bulk Email Removal
Generally removing unwanted emails on an organization-wide scale