What you are evaluating
The scored configuration is Microsoft 365 API deployment with auto-moves. Inline link modification and gateway quarantine are outside that scope; API scanning starts after inbox delivery.
A useful evaluation context
Consider for teams comparing email protection alongside an existing Cloudflare environment or evaluating explicit API-versus-gateway deployment tradeoffs.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Deployment guidance distinguishes API, BCC or journaling, and MX modes.
- Auto-move policies map dispositions to actions such as junk, trash or recoverable deletion.
- The Email Security API provides message search, details and supported action endpoints.
Where it fits in the work
- Review API permissions and mailbox scope before connection.
- Configure a reversible disposition-based action in a test mailbox.
- Inspect message details and completed-action results, including any delay from provider throttling.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A synthetic suspicious message lands in a test inbox before analysis completes.
Evidence to look for
Record inbox arrival and auto-move completion separately, then restore the harmless message using the documented provider-compatible path.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Does this deployment require a routing change or mailbox read/write permission?
- How is a failed or delayed mailbox action surfaced?
- Which retention and provider recovery rules govern the selected delete action?
Names you may encounter: Area 1. Historical names do not establish current availability or feature equivalence.