We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Tenant Allow/Block List
Tenant Allow/Block List, UAE

Blocking a domain also stops your own people emailing it. Most teams find that out from a bounce message.

Block entries for domains and email addresses prevent users in your organisation from sending to them, and the entire message is blocked for every recipient even if only one address matches. The Tenant Allow/Block List is powerful, and it behaves in ways that are worth knowing first.

Book an allow and block list reviewSee how it behaves
Tenant Allow Block List management for UAE organisations
  • 5 minutesBefore a new entry starts working
  • 30 daysDefault block entry expiry, up to 90 or never
  • 45 daysHow long submission allow entries are kept
  • Blocks winBlock entries take precedence over allows
What the list actually does

Eight behaviours that determine whether this helps or hurts.

The Tenant Allow/Block List overrides the filtering verdict manually, during mail flow for email and at time of click for email, Teams and Office apps. Every entry is a deliberate weakening or strengthening of the filter, and several of them do more than the name suggests.

Blocks take precedence over allows

Stated directly, and it resolves most confusion about why an allowed sender is still being quarantined. If a message contains a URL or domain that is blocked, it can be classified as high confidence phishing and quarantined even when the sender is legitimate.

A domain block stops outbound mail too

Block entries for domains and email addresses also prevent your users from sending to them. The bounce is explicit, a 550 5.7.703 non-delivery report naming the Tenant Allow Block List, and the entire message is blocked for all recipients even if only one address matched.

It matches the From address, not the envelope sender

Entries apply to the From address, the 5322.From or P2 sender, rather than the MAIL FROM address, the 5321.MailFrom or envelope sender. That distinction matters when you are blocking something that forges one and not the other, and it is a common source of entries that do not work.

Blocking makes something high confidence phishing

Blocking a sender or domain here treats those messages as high confidence phishing, which carries the strictest quarantine handling. If you want them treated as spam instead, the blocked senders or blocked domains list in anti-spam policies is the right place, not this one.

Expiry, which differs by entry type

Blocks on domains and addresses, files and URLs expire after 30 days by default and can be set up to 90 days or to never expire. Blocks on spoofed senders, IP addresses and Teams domains never expire at all, which means they accumulate unless somebody reviews them.

Allows you cannot create directly

For malware and high confidence phishing verdicts you cannot create an allow entry here. You submit through the Submissions page and confirm the item is clean, and the allow entry is created from that. Files cannot be allowed directly at all, only through submission.

Allows expire, and are removed when unnecessary

Allow entries for domains and addresses, files and URLs are kept for 45 days after the filtering system determines the entity is clean, then removed. You can also set them to expire up to 30 days after creation. Spoofed sender allow entries never expire.

Microsoft cleans up after you, and tells you

If Microsoft determines an allow entry is no longer needed, the entry is automatically removed and the built-in threat management alert policy named Removed an entry in Tenant Allow/Block List creates an alert. That alert is worth routing somewhere, because it is genuinely useful.

The behaviour that generates the ticket

One blocked recipient blocks the whole message, for everyone on it.

This is the outbound half of a block entry, and it is the part almost nobody expects when they block a domain for inbound reasons.

  • Block entries for domains and email addresses prevent users in the organisation from sending email to those blocked domains and addresses. Senders receive a non-delivery report reading 550 5.7.703, naming the Tenant Allow Block List as the cause, which at least makes it diagnosable.
  • The scope is wider than the match. Microsoft states the entire message is blocked for all internal and external recipients, even if only one recipient email address or domain is defined in a block entry. So one blocked address on a distribution of twenty stops the message reaching any of them.
  • The related point is severity. Blocking a sender or domain in this list treats those messages as high confidence phishing, which is the strictest handling in the product. If the intent was simply to reduce nuisance mail, the blocked senders and blocked domains lists in anti-spam policies express that far better.
  • IP and Teams blocks are more absolute again. A manual IP block drops all incoming mail from that address at the edge of the service. A Teams block blocks incoming communication from that domain and address and deletes existing communication. Neither expires by default.
Ask us to audit your block entries
How we approach it

Four principles for a list that stays useful.

Every entry here is a permanent exception to a filter that Microsoft updates continuously. The default assumption should be that an entry is temporary and that removing it is the goal.

We prefer submissions to manual allow entries

Submitting a false positive and confirming it is clean creates the allow entry as a consequence of a Microsoft judgement, and it also improves the filter for everyone. A manual allow entry only weakens your own filtering. Where both routes exist, the submission route is better in both directions.

We check the outbound consequence of every domain block

Users cannot send to a blocked domain, and the entire message fails for every recipient even if one address matched. A domain blocked during an incident three years ago can quietly break communication with a company you now supply, and the only symptom is a bounce nobody escalates.

We give special attention to entries that never expire

Blocks on spoofed senders, IP addresses and Teams domains never expire, and IP blocks drop mail at the edge of the service while Teams blocks delete existing communication. Those are the entries most likely to be both forgotten and consequential, so they get reviewed first.

We match severity to intent

Blocking here treats messages as high confidence phishing. Where the actual intent was to stop nuisance mail, the blocked senders and blocked domains lists in anti-spam policies are the right instrument. Using the strictest control for a mild problem creates quarantine handling nobody wanted.

How a review runs

Four phases across roughly three weeks.

Short and high value. Most tenants have accumulated entries over years, and a meaningful proportion are either unnecessary, actively harmful, or blocking something the business now needs.
  1. 01
    Week 1

    Export and attribute every entry

    All six entry types, with what each was for, who added it and when. Entries that never expire, meaning spoofed senders, IP addresses and Teams domains, get particular attention because they persist indefinitely without anybody deciding they should.

    • Full export across all entry types
    • Never-expiring entries identified
    • Attribution attempted per entry
    • Entries with no owner or reason listed
  2. 02
    Week 2

    Assess the allow entries as risk

    Unnecessary allow entries expose the organisation to mail the system would otherwise filter, so each one needs justification. Allows created through submissions are less concerning because they exist as a result of a Microsoft judgement, and they age out.

    • Each allow entry justified or removed
    • Submission-created allows distinguished from manual ones
    • Expiry set where entries were left permanent
    • Attack simulation URLs moved to advanced delivery policy
  3. 03
    Week 2 to 3

    Assess the block entries for collateral

    The outbound consequence checked for every domain block, since users cannot send to a blocked domain and the whole message fails for every recipient. Severity checked too, because blocking here means high confidence phishing rather than spam.

    • Outbound impact assessed per domain block
    • Blocks better expressed as anti-spam entries identified
    • Never-expiring blocks reviewed and dated
    • IP and Teams blocks confirmed as still intended
  4. 04
    Week 3

    Set the operating process

    A route for adding entries that captures reason and owner, a preference for submissions over manual allows, and the Removed an entry in Tenant Allow/Block List alert routed to somebody. Otherwise the list starts accumulating again immediately.

    • Entry request and approval process defined
    • Submissions preferred over manual allow entries
    • Removal alert routed to a named owner
    • Recurring review scheduled
Where this matters

Six situations where this list is the cause or the cure.

The list is usually invisible until it produces a symptom, and the symptom is rarely attributed to it without somebody knowing to look.

A business that cannot email a customer

The bounce says 550 5.7.703 and names the Tenant Allow Block List, which is at least diagnosable once somebody reads it. The cause is almost always a domain blocked during an old incident, and the fix is a minute once the connection is made.

An organisation whose allowed sender keeps getting quarantined

Block entries take precedence over allow entries, so a URL or domain blocked somewhere in the list overrides the sender allow. Microsoft advises reviewing block entries for URLs or domains in the affected messages, which is exactly the right first step.

A regulated firm auditing its filtering exceptions

Every allow entry is a documented weakening of a control, and an auditor asking why one exists is a reasonable question. Being able to answer per entry, with a reason and an owner, is the difference between a clean finding and an uncomfortable conversation.

An operator running phishing simulations

Microsoft is explicit that URL allow entries should not be used for phishing URLs from non-Microsoft attack simulation training, and that the advanced delivery policy is the right place instead. Simulation URLs sitting in the allow list are a genuine exposure rather than a tidiness issue.

A company that inherited a tenant

After an acquisition or a change of provider, the list arrives with entries nobody can explain, some of which never expire. Attribution and review is one of the higher-value early tasks, because IP blocks and Teams blocks in particular have effects that persist silently.

A business submitting the same false positive repeatedly

For URLs this is usually unnecessary. Reporting one URL covers its variations, so reporting www.contoso.com/abc also covers the same path with query strings and additional segments. Knowing that removes a recurring task that several people were quietly doing.

Three positions

How UAE organisations manage manual overrides.

The right column is the most common: entries added during incidents by whoever was on shift, never reviewed, and gradually becoming a second filtering policy nobody designed.
Every entry has a reason recorded
Managed with a processYes
Reviewed occasionallySome
Accumulated over yearsNo
Allow entries justified
Managed with a processIndividually
Reviewed occasionallyRarely
Accumulated over yearsNo
Submissions preferred over manual allows
Managed with a processYes
Reviewed occasionallySometimes
Accumulated over yearsNo
Never-expiring entries reviewed
Managed with a processOn a schedule
Reviewed occasionallyNo
Accumulated over yearsNo
Outbound impact of blocks understood
Managed with a processYes
Reviewed occasionallyPartly
Accumulated over yearsDiscovered via NDR
Severity chosen deliberately
Managed with a processPhishing or spam as intended
Reviewed occasionallyDefault
Accumulated over yearsDefault
Attack simulation URLs handled correctly
Managed with a processAdvanced delivery policy
Reviewed occasionallySometimes here
Accumulated over yearsHere
Removal alerts monitored
Managed with a processYes
Reviewed occasionallyNo
Accumulated over yearsNo
List size trending
Managed with a processStable
Reviewed occasionallyGrowing
Accumulated over yearsGrowing
Risk from stale allows
Managed with a processLow
Reviewed occasionallyModerate
Accumulated over yearsUnknown
Feature
Managed with a process
Reviewed occasionally
Accumulated over years
Every entry has a reason recorded
YesSomeNo
Allow entries justified
IndividuallyRarelyNo
Submissions preferred over manual allows
YesSometimesNo
Never-expiring entries reviewed
On a scheduleNoNo
Outbound impact of blocks understood
YesPartlyDiscovered via NDR
Severity chosen deliberately
Phishing or spam as intendedDefaultDefault
Attack simulation URLs handled correctly
Advanced delivery policySometimes hereHere
Removal alerts monitored
YesNoNo
List size trending
StableGrowingGrowing
Risk from stale allows
LowModerateUnknown
Behaviour by entry type

Ten differences worth knowing before you add an entry.

The list is not one feature with six tabs. Each entry type has its own verdict, its own expiry behaviour and its own creation route.
Entry typeBlock behaviourBlock expiry
Domains and email addressesTreated as high confidence phishing, quarantined30 days default, up to 90 or never
FilesBlocked as malware, quarantined30 days default, up to 90 or never
URLsBlocked as high confidence phishing, quarantined30 days default, up to 90 or never
Spoofed sendersManual override of a spoof intelligence allowNever expires
IP addressesAll incoming mail dropped at the service edgeNever expires
Teams domains and addressesCommunication blocked and existing communication deletedNever expires
Allow, domains and addressesDirect creation only for bulk, spam and phishingKept 45 days after judged clean
Allow, URLsDirect creation only for the same verdictsKept 45 days after judged clean
Allow, filesCannot be created directly, submission onlyKept 45 days after judged clean
Allow, spoofed sendersCan be created proactivelyNever expires
How an engagement runs

Five steps, and most of the value is in the first two.

Exporting and attributing the list is quick and it consistently finds something that is either weakening the filter or breaking legitimate mail.
  1. 1

    Export every entry type and attribute what you can

    Domains and email addresses, files, URLs, spoofed senders, IP addresses and Teams domains. Each with a date, an author where the record exists, and a reason. Entries nobody can explain are recorded as such rather than removed immediately.

  2. 2

    Assess allow entries individually

    Unnecessary allow entries expose the organisation to mail the system would otherwise filter. Manual allows get the closest scrutiny, submission-created allows less so since they follow a Microsoft clean judgement and age out after 45 days.

  3. 3

    Assess block entries for outbound and severity impact

    Every domain block checked for whether the organisation now needs to email that domain, since outbound is blocked and the whole message fails. Severity checked too, because a block here means high confidence phishing rather than spam.

  4. 4

    Fix the misplaced entries

    Attack simulation URLs moved to the advanced delivery policy, nuisance senders moved to anti-spam blocked lists where phishing severity was never intended, and expiry set on entries that were left permanent without a reason.

  5. 5

    Put a process and an alert in place

    A request route capturing reason and owner, submissions preferred over manual allows, the Removed an entry in Tenant Allow/Block List alert routed to somebody, and a recurring review so the list does not simply refill over the next two years.

Straight answers

What organisations ask about the Tenant Allow/Block List.

Because that is what a block entry does. Block entries for domains and email addresses also prevent users in your organisation from sending to them, and senders receive a 550 5.7.703 non-delivery report naming the Tenant Allow Block List. It is one entry with two effects.

By design. Microsoft states the entire message is blocked for all internal and external recipients, even if only one recipient email address or domain is defined in a block entry. So a single blocked address on a large distribution stops the message reaching anybody.

Almost certainly a block entry elsewhere. Block entries take precedence over allow entries, and a message containing a blocked URL or domain can be classified as high confidence phishing and quarantined even when the sender is legitimate. Review your block entries for anything in the affected messages.

No, and this catches people. Entries apply to the From address, the 5322.From or P2 sender, not the MAIL FROM address, the 5321.MailFrom or envelope sender. If you built an entry expecting envelope matching, it will not behave the way you intended.

Not directly. For malware and high confidence phishing verdicts you cannot create allow entries in the list. You use the Submissions page, confirm the item is clean, and the allow entry is created from that. Files cannot be allowed directly at all, only through submission.

It varies. Blocks on domains and addresses, files and URLs default to 30 days and can be set up to 90 days or to never expire. Blocks on spoofed senders, IP addresses and Teams domains never expire. Allow entries from submissions are kept 45 days after the system judges the entity clean.

Within 5 minutes of adding an allow entry on the Submissions page or a block entry in the list. That is fast enough for incident response, which is useful to know when you are deciding whether to reach for this or for a transport rule.

Yes, for allows. If Microsoft determines an allow entry is no longer needed, the entry is automatically removed and the built-in threat management alert policy named Removed an entry in Tenant Allow/Block List creates an alert. Route that alert somewhere, because it is the cleanup working as intended.

Usually not. Blocking here treats those messages as high confidence phishing, which is the strictest handling. To treat them as spam instead, add the sender to the blocked senders list or blocked domains list in anti-spam policies. Match the instrument to the actual problem.

No. For URLs reported as false positives, subsequent messages containing variations of the original URL are allowed. Reporting www.contoso.com/abc covers the same path with query strings and additional segments, so one submission is sufficient.

They should not be here. Microsoft states that to allow phishing URLs from non-Microsoft attack simulation training you should not use URL allow entries in the Tenant Allow/Block List, and should use the advanced delivery policy to specify the URLs instead.

It depends what blocked the message. If user or mailbox intelligence impersonation protection blocked it, no allow entry is created in this list. Instead the domain or sender is added to the trusted senders and domains section of the anti-phishing policy that detected the message.

It bypasses IP-based filtering checks such as connection filtering and IP reputation checks. It does not change message throttling behaviour. An IP block entry, conversely, rejects messages at the service edge, which is the most absolute block available in the list.

At least quarterly, and the never-expiring types more carefully than the rest. Spoofed sender, IP address and Teams entries persist indefinitely and their effects are significant, particularly Teams blocks which delete existing communication as well as blocking new.

We scope by how many entries exist and how much attribution effort they need. The free first step: export your list and count how many entries you can explain. Most organisations get part way down the list and stop, which is the honest starting point for a review.

Not every check, and this is worth understanding. During mail flow or time of click, if messages containing the allowed entities pass other checks in the filtering stack, they are delivered, with the filters associated with the allowed entities skipped. Other filters still apply.

Fast enough to be useful. After you add an allow entry on the Submissions page or a block entry in the list, the entry starts working within 5 minutes. That makes it a legitimate incident response tool rather than something to configure afterwards.

Under email and collaboration, in policies and rules, threat policies, in the rules section. It is worth knowing the direct route, because the list is not somewhere people navigate to routinely and finding it during an incident wastes minutes that matter.
Review questions

Fifteen questions about your own list.

The first group usually cannot be answered, and that is the finding. Entries accumulate through incidents and nobody records why afterwards.

Inventory

  • How many entries exist in total?
    Across all six types.
  • How many never expire?
    Spoof, IP and Teams entries do not.
  • Can we say why each was added?
    Usually not.
  • Who added them?
    And are they still here.
  • Any IP blocks still in place?
    They drop mail at the edge.

Allows

  • How many manual allow entries do we have?
    Each weakens the filter.
  • Were they created by submission?
    Preferable to manual.
  • Do any have no expiry?
    Set one where you can.
  • Are attack simulation URLs in here?
    They belong in advanced delivery.
  • Do we see the automatic removal alerts?
    Route them somewhere.

Blocks

  • Do any block domains we now do business with?
    Outbound would fail.
  • Should any of these be anti-spam entries instead?
    For spam rather than phishing severity.
  • Have we tested sending to a blocked domain?
    The NDR is 550 5.7.703.
  • Do we block on From or expect envelope matching?
    It is the From address.
  • Are Teams blocks still appropriate?
    They delete existing communication.
Related reading

The pages around this one.

Quarantine policies

What happens to a message once a block sends it to quarantine.

Learn more

Anti-phishing policies

The detection layer these entries override.

Learn more

Email security audit

A full review of the mail protection configuration.

Learn more
Next step

Export your list and count how many entries you can actually explain.

Then check whether any blocked domain is one you now need to email, because outbound is blocked too and the bounce is easy to miss. Both checks take under an hour.

Book an allow and block list reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Quarantine Policies

Who can see, act on and release blocked mail

Learn more

Anti-Phishing Policies

Impersonation protection, spoof handling and thresholds

Learn more

Email Security Audit

Authentication, policy, exceptions, routing, mailboxes

Learn more

Defender for Office 365

Plan 1 versus Plan 2, and the ten second way to tell which you have

Learn more

DMARC Audit UAE

Stop exact-domain spoofing, and keep your mail delivering

Learn more

Safe Links

Time-of-click URL checks in mail, Teams and Office

Learn more

Attack Simulation Training

Phishing simulation you probably already own, including QR codes

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy