Transport Rules Should Not Bypass Security Controls
K
Kenny Maurer
We should be able to specify named exclusions instead of Accept Risk.
For example if we deploy the transport rules with cipp, we can make sure that exactly the same policy is applied to every tenant. We do this for Security Awareness Training.
Accepting Risk feels like the wrong approach because then it does not scan for new or other transport rules which may be not intended.