Multi-Account Risky Policy Remediation
MSP administrators can now remove risky email policies across multiple managed accounts at once in Email Protection. Risky policies are overly broad allow rules that can bypass email security checks, such as allowing all email from a broad external domain like vendor.com. This lets you fix these rules across all accounts instead of repeating the same cleanup account by account.
When risky policies are found across your managed accounts, a Risky policies found across accounts card appears on the Policies page. Click the card to review and remove risky policies across all accounts.
Before you begin
You must be an MSP administrator with access to multiple managed accounts.
The multi-account view appears only when risky policies are found across your managed accounts.
This process permanently deletes the flagged risky policies you choose to remove. It cannot be undone.
If you are managing only one account, see Risky Policies Detection and Remediation.
How to access the multi-account view
Open Email Protection from Email Gateway Defense, Impersonation Protection, or Incident Response.
Click Policies in the left-hand navigation.
At the top of the page, look for the Risky policies found across accounts card (the one with the groups icon) to open the multi-account view.
After you click the card, a short transition screen appears to show that you are moving from a single account view to an all-accounts view. When the transition completes, Email Protection opens the multi-account risky policies list.
Reviewing risky policies across all accounts
The multi-account list shows the managed accounts that have risky policies and how many matching policies were found in each one.
Each row shows an account name and the number of matching policies.
The list loads all accounts with risky policies at once. The Delete all button becomes available when the list is ready.
If you are unsure which policies are risky, start with Delete all. Bulk deletion removes only the policies flagged as risky and does not affect your other email policies.
If you want to inspect a single account first, return to the Policies page and click the Risky policies found card. This opens the risky policies for the account you are currently managing.
Deleting risky policies across all accounts
In the multi-account list, click Delete all.
Review the confirmation message. It shows how many matching policies will be deleted across how many accounts.
To proceed, click Delete all. To cancel, click Cancel or navigate away from the page.
If you try to leave the page, a Leave this page? dialog appears warning that unsaved changes will be lost. Click Stay to remain on the page, or click Leave to exit without making changes.
Email Protection processes all accounts and shows the result when complete.
After deletion completes
Note: After deleting policies, the risky policy count in BarracudaONE may not immediately match the Email Protection Policies page. This is expected as Email Protection updates in real time, while BarracudaONE syncs separately. A temporary count difference does not mean the deletion failed. The Email Protection Policies page is the authoritative view of your current risky policies.
When processing finishes, each account is marked as completed or shows an error.
To retry failed accounts immediately, click Retry. Accounts that completed successfully are not processed again.
To return to the Policies page, click Done.
If all risky policies were deleted successfully, the multi-account warning card is no longer shown.
If some risky policies remain, the card stays visible so you can return and continue remediation later.
Deleting risky policies for one account
If you only need to address risky policies for the account you are currently managing, you do not need to use the multi-account view. On the Policies page, click the Risky policies found card instead. This opens the risky policies for that account only.
Review the risky policies shown for that account. For user-level sender policies, the associated user is displayed alongside the policy details. This allows you to identify and contact the affected user before removing the policy.
Click Delete all to remove the flagged risky policies for that account only. Alternatively, delete each policy individually by using the trash can icon next to the policy you want to remove.
Confirm the deletion.
When you return to the Policies page, the warning cards update to reflect the changes. If risky policies remain across other accounts, the Risky policies found across accounts card will still be shown.
For more details on single-account risky policy remediation, see Risky Policies Detection and Remediation.
Important notes
From the multi-account overview, deletion applies to all accounts at once. You cannot select individual accounts or individual policies.
Deletion across a large number of accounts may take longer to complete.
If you cancel before confirming deletion, no changes are made. Once deletion begins, the cancel option is no longer available.
The risky policy count in BarracudaONE is updated separately from Email Protection and may not immediately reflect recent changes. The Email Protection Policies page always shows the current state.
If the risky policy data fails to load – for example, due to a temporary service issue – an error message is displayed with a Retry button. Click Retry to attempt loading the data again. If the issue persists, try again later or contact Barracuda Networks Technical Support.