---
title: Defender for Email Anti-Spam Policy Creation
description: This guide will provide background information on creating an anti-spam threat policy that will monitor spam detection for inbound and outbound mail flow.
---

[Skip to content](https://knowledge.sittadel.com/defender-for-email-anti-spam-policy-creation#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en)
3. [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)

# Defender for Email Anti-Spam Policy Creation

## This guide will provide background information on creating an anti-spam threat policy that will monitor spam detection for inbound and outbound mail flow.

### **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-04-16-2156-PM.png?width=125&height=133&name=image-png-Jan-19-2024-04-04-16-2156-PM.png)Role Requirements**

Procedure Scope: **Administrators**

Required Group Membership: **Admin.Security**

**![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-29-09-3760-PM.png?width=670&height=5&name=image-png-Jan-19-2024-04-29-09-3760-PM.png)**

**Creating an Anti-Spam Threat Policy**

1. Navigate to the [Anti-Spam Policies – Microsoft Defender](https://security.microsoft.com/antispam) portal, locate and select the **Create policy** action,specify if the policy is for **Inbound** or **Outbound** enforcement  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-30-2024-09-21-31-9902-PM.png?width=670&height=327&name=image-png-Nov-30-2024-09-21-31-9902-PM.png)**
2. You will supply basic identification information such as the **Name** and **Description** for the policy. Select **Next** to proceed.  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-30-2024-09-21-45-4181-PM.png?width=670&height=356&name=image-png-Nov-30-2024-09-21-45-4181-PM.png)**
3. You will be able to configure **Internal Users**, **Groups**,or **Domains Assignments** or **Exclusions** for the policy, this section will outline the selected groups that will be in scope to have the email security deployed. Select **Next** to proceed.  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-30-2024-09-22-30-1967-PM.png?width=670&height=356&name=image-png-Nov-30-2024-09-22-30-1967-PM.png)**
4. A list of all the possible configuration settings will be listed, make sure to apply the necessary settings to fit the needs of your organization. Select **Next** to continue.  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-30-2024-09-22-40-9968-PM.png?width=670&height=356&name=image-png-Nov-30-2024-09-22-40-9968-PM.png)**
5. You can specify the actions that will be taken on the messages that are flagged as spam, these can be adjusted to redirect the message, direct the message to junk folder, quarantine, etc. Select **Next** to proceed.  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-30-2024-09-22-51-0382-PM.png?width=670&height=355&name=image-png-Nov-30-2024-09-22-51-0382-PM.png)**
6. You will be given the option to create your own Allowed / Blocked senders list for incoming messages, this list will be consulted for spam related incidents. Select **Next** to continue to revisions.  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-30-2024-09-22-58-7865-PM.png?width=670&height=356&name=image-png-Nov-30-2024-09-22-58-7865-PM.png)**
7. The review page will allow you to see all configured settings for the policy, if you detect a discrepancy at this stage make note of the section and select **Back** to go to the previous sections to make the necessary alterations before finalization. If everything checks out, select **Submit** to publish the threat policy.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-30-2024-09-23-06-7110-PM.png?width=670&height=355&name=image-png-Nov-30-2024-09-23-06-7110-PM.png)
8. A prompt will be displayed detailing that the policy has been created and has been put into immediate effect. Select **Done** to finalize the creation process.  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-30-2024-09-25-51-0941-PM.png?width=670&height=356&name=image-png-Nov-30-2024-09-25-51-0941-PM.png)**

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>