Applies to: Exchange Server 2013
Topic Last Modified: 2012-10-11
By default, malware filtering is enabled in Microsoft Exchange Server 2013. The default anti-malware policy controls your company-wide malware filtering settings. As an administrator, you can view and edit, but not delete, the default anti-malware policy so that it is tailored to best meet the needs of your organization.
What do you need to know before you begin?
- We recommend that you manually download anti-malware engine and
definition updates on your Exchange server prior to placing it in
production. For more information, see Download Engine and
Definition Updates.
- You need to be assigned permissions before you can perform this
procedure or procedures. To see what permissions you need, see the
“Anti-malware” entry in the Anti-Spam and
Anti-Malware Permissions topic.
- For information about keyboard shortcuts that may apply to the
procedures in this topic, see Keyboard Shortcuts in
the Exchange Admin Center.
Tip: |
---|
Having problems? Ask for help in the Exchange forums. Visit the forums at: Exchange Server, Exchange Online, or Exchange Online Protection |
Use the EAC to configure the default anti-malware policy
- In the EAC, navigate to Protection > Malware
filter, and then double-click the default policy.
- Click the Settings menu option. In the Malware
Detection Response section, use the option buttons to select
the action to take when malware is detected in a message:
- Delete the entire message Prevents the
entire message, including attachments, from being delivered to the
intended recipients. This is the default value.
- Delete all attachments and use default alert
text Deletes all message attachments, not just
the infected one, and inserts the following default alert text into
a text file that replaces the attachments: “Malware was detected in
one or more attachments included with this email. All attachments
have been deleted.”
- Delete all attachments and use custom alert
text Deletes all message attachments, not just
the infected one, and inserts a custom message into a text file
that replaces the attachments. Selecting this option enables the
Custom alert text field where you must type a custom
message.
Important: If malware is detected in the message body, the entire message, including all attachments, will be deleted regardless of which option you select. This action is applied to both inbound and outbound messages. - Delete the entire message Prevents the
entire message, including attachments, from being delivered to the
intended recipients. This is the default value.
- In the Notifications section, you have the option to
send a notification email message to senders or administrators when
a message is detected as malware and is not delivered. These
notifications are only sent when the entire message is deleted.
- In the Sender Notifications section, select the check
boxes to Notify internal senders (those within your
organization) or to Notify external senders (those outside
your organization) when a detected message is not delivered.
- Similarly, in the Administrator Notifications section,
select the check boxes to Notify administrator about undelivered
messages from internal senders or to Notify administrator
about undelivered messages from external senders. Specify the
email address or addresses of the administrator in their respective
Administrator email address fields after selecting one or
both of these check boxes. Use a semicolon to separate multiple
addresses.
The default notification text is “This message was created automatically by mail delivery software. Your email message was not delivered to the intended recipients because malware was detected.” The language in which the default notification text is sent is dependent on the locale of the message being processed.
- In the Customize Notifications section, you can create
customized notification text to be used in place of the default
notification text for sender and administrator notifications.
Select the Use customized notification text check box, and
then specify values in the following required fields:
- From name The name you want to be used
as the sender of the customized notification.
- From address The email address you want
to be used as the sender of the customized notification.
- Messages from internal senders The
Subject and Message of the notification if the
detected message originated from an internal sender.
- Messages from external senders The
Subject and Message of the notification if the
detected message originated from an external sender.
Note: The default Subject text is “Undeliverable message.”
- From name The name you want to be used
as the sender of the customized notification.
- Click Save. A summary of your default policy settings
appears in the right pane.
- In the Sender Notifications section, select the check
boxes to Notify internal senders (those within your
organization) or to Notify external senders (those outside
your organization) when a detected message is not delivered.
How do you know this worked?
The following procedure provides instructions for using the EICAR.TXT antivirus test file to verify that malware filtering is working correctly.
Important: |
---|
The EICAR.TXT file is not a virus. However, because users often have the need to test that installations function correctly, the antivirus industry, through the European Institute for Computer Antivirus Research, has adopted the EICAR standard in order to meet this need. |
- Create a new text file, and then name the file EICAR.TXT.
- Copy the following line into the text file:
Copy Code X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
Note: If you are using a desktop antivirus program, make sure that the folder you are saving the file to is excluded from scanning. - Attach this file to an email message that will be filtered by
Exchange 2013.
Check the recipient mailbox of the test message. Depending on the malware detection response you have configured, the entire message will be deleted, or the attachment will be deleted and replaced with the alert text file. Any configured notifications will also be distributed.
- Delete the EICAR.TXT file after testing is completed so that
other users are not unnecessarily alarmed.