Known Behaviors and FAQs
This page describes known behaviors and answers common questions about Email Gateway Defense that you may encounter during normal use. These items are documented for clarity when the behavior is expected, is not considered a bug, or is not planned for change in the near term. If what you are seeing matches a behavior listed here and your service is otherwise working as expected, no action is needed.
Microsoft Entra ID Sync Count and Date Variations
During Microsoft Entra ID (formerly Azure AD) synchronization:
Updated count: May appear higher than expected because the count includes distribution lists and groups in addition to individual user accounts.
Sync date: May show an older timestamp even after synchronization completes successfully.
If all expected users appear correctly in the Users list and email routing functions normally, this behavior does not indicate an issue.
Outbound Quarantine Message Count
The quarantined outbound message count may not match the number of items listed on the Outbound Quarantine page:
Delivered or deleted messages: When an administrator delivers or deletes a quarantined outbound message, the item is removed from the Outbound Quarantine message log to highlight items still requiring action.
Display count: The total count reflects all outbound messages quarantined within the selected period and does not decrease when messages are delivered or deleted.
Any upcoming improvements to count synchronization will be documented in the Email Gateway Defense Release Notes.
Query Defaults and Retention:
By default, the Outbound Quarantine displays data from the last 2 days.
Search queries and displayed counts are limited to outbound messages received within the last 30 days.