Integrations
- Integrations
- 1Password
- Abnormal
- Absolute
- AbuseIPDB
- Adaptive Shield
- Adobe Cloud
- ADP
- Agari Phishing Response
- Airlock
- Airlock Digital
- Akamai Identity Cloud Social
- Alert Logic
- AlgoSec Firewall Analyzer
- AlienVault OTX
- AlienVault USM
- Anodot
- Ansible
- Anvilogic
- Any Run
- Apex One
- ArcSight ESM
- Area 1
- Asana
- Asset Panda
- Atlassian User Management
- Atlassian User Provisioning
- auth0
- Authentik
- Authomize
- Automox
- AWS
- AWS IAM Identity Center
- Axonius
- Azure
- Azure Data Explorer
- Azure DevOps
- Azure Log Analytics
- Azure Storage
- BambooHR
- Big Fix
- BigPanda
- Bitbucket
- Bitdefender
- Bitsight
- Bitwarden
- Black Duck
- Black Kite
- Blink
- BMC Remedy
- Box
- Brinqa
- Cato Networks
- Censys
- Check Point Harmony
- Check Point Infinity Events
- Check Point XDR-XPR
- Check Point Management
- Checkmarx One
- Checkmarx SAST
- Chorus
- Chronicle
- Cisco Advanced Phishing Protection
- Cisco Domain Protection
- Cisco Meraki
- Cisco Talos
- Cisco Umbrella
- Cisco Webex
- Claroty xDome
- ClearPass
- ClickHouse
- ClickUp
- Cloud Custodian
- Cloudflare
- Cobalt
- Compass
- Confluence
- Confluence Data Center
- Coralogix
- Coralogix Incident Management
- Cortex XDR
- Cortex Xpanse
- CredStash
- Cribl
- CrowdStrike
- CyberArk
- Cybersixgill
- CyCognito
- Cyera
- Cylance
- Cyware CTIX
- Darktrace
- Dasera
- Databricks
- Datadog
- DataSet
- Delighted
- Delinea
- Devo
- Discord
- Docusign
- Domo
- Drata
- Dropbox
- Dropbox Business
- Druva
- Duo
- Duo Auth
- Dynatrace
- EasyVista
- EchoTrail
- Egnyte
- Egnyte Secure Govern
- Elasticsearch
- Entro
- Ermetic
- Exabeam
- Exchange Online
- Exchange Online
- Actions
- Expel
- F5 BIG IP
- Falcon LogScale
- Falcon Surface
- Flare.io
- Forcepoint DLP
- Forescout
- FortiGate
- Freshservice
- GCP
- Ghostwriter
- Git
- GitHub
- GitLab
- Glean
- Gmail
- Google Calendar
- Google Chat
- Google Docs
- Google Drive
- Google Forms
- Google Looker
- Google Meet
- Google Sheets
- Google Workspace
- Grafana
- Grip Security
- GYTPOL
- Have I Been Pwned
- HiBob
- HubSpot
- Hunters
- Hybrid Analysis
- Hyperproof
- IBM Cloud
- IBM NS1 Connect
- IBM X Force
- Imperva
- incident.io
- Infoblox Cloud Services Portal
- Integrations
- Intercom
- Intezer
- IP API
- IPinfo
- IPWHOIS
- Ironscales
- Ivanti RiskSense
- Jamf
- JetBrains
- JFrog
- Jira
- Jira Data Center
- Joe Sandbox
- JumpCloud
- Kandji
- Keeper Secrets Manager
- Kenna Security
- KnowBe4
- KnowBe4 Events
- Kubernetes
- Lacework
- LaunchDarkly
- Linear
- Litmos
- LogicMonitor
- LogRhythm
- Manage Engine ServiceDesk Plus
- Mattermost
- Maven
- Microsoft Defender For Cloud
- Microsoft Defender For Cloud Apps
- Microsoft Defender For Endpoints
- Microsoft Defender XDR
- Microsoft E-Discovery
- Microsoft Entra ID
- Microsoft Graph
- Microsoft Intune
- Microsoft Office 365 Management Activity
- Microsoft Outlook
- Microsoft Purview
- Microsoft Sentinel
- Microsoft SQL Server
- Microsoft Teams
- Mimecast
- MISP
- Monday
- MongoDB Atlas
- MxToolbox
- Neo4j
- NetBox
- Netography
- Netskope
- New Relic
- Nightfall AI
- NinjaOne
- Notion
- Nozomi Networks
- Nuclei
- Nucleus
- Nutanix Hypervisor
- Obsidian
- Okta
- OneDrive
- OneLogin
- OneTrust
- OpenAI
- OpenCTI
- Opsgenie
- OPSWAT
- Oracle Cloud
- Oracle HCM
- Orca Security
- OWASP ZAP
- PagerDuty
- Palo Alto Cloud NGFW
- Palo Alto Firewall
- Panther
- Pentera
- Perception Point
- PhishLabs
- PhishLabs Incident Data
- PhishLabs Open Web Monitoring
- Pingdom
- PingID
- PingOne
- PlexTrac
- PortSwigger
- Postman
- Postman SCIM
- Power BI
- PowerShell
- Prisma Access
- Prisma Cloud CSPM
- Prisma Cloud CWP
- Prometheus
- Proofpoint
- Proofpoint ITM
- Proofpoint Protection Server
- Proofpoint Security Awareness Training
- Proofpoint TAP
- Proofpoint Threat Response Auto Pull
- Pub-Sub
- QRadar
- Qualys
- Rapid7
- Rapid7 InsightIDR
- Rapid7 InsightVM Cloud
- Rapid7 Threat Command
- Reco
- Recorded Future
- Red Hat IdM
- Rippling
- runZero
- SafeBase
- Sage HR
- SailPoint
- SailPoint IdentityIQ
- Salesforce
- SAP Ariba
- ScienceLogic
- Securin
- Securin VI
- SecurityScorecard
- Securonix
- SemGrep
- SentinelOne
- ServiceNow
- SharePoint
- Shodan
- Shopify
- Silverfort
- Slack
- Smartsheet
- Snipe-IT
- Snowflake
- Snyk
- SolarWinds Service Desk
- SonarQube
- Sophos
- Split
- Splunk
- Splunk Observability
- Splunk SOAR
- Spur
- StrongDM
- Sumo Logic
- Symantec EDR
- Sysdig
- Tableau
- Tanium
- TeamCity
- TeamViewer
- Telegram
- Tenable
- Tenable Security Center
- Terraform
- Terraform Cloud
- TheHive
- Thinkst Canary
- ThreatQuotient
- Trellix Email Security
- Trello
- Trend Vision One
- Twilio
- UKG HR
- Uptycs
- URLScan
- Vault
- Veracode
- Verkada
- Vertica
- VirusTotal
- VMware Carbon Black
- VMware vSphere
- WeChat
- WhatsApp
- Whois
- WildFire
- Wiz
- Workday
- Workspace ONE UEM
- YesWeHack
- Zendesk
- Zero Networks
- Zoom
- Zscaler Internet Access
- Zscaler Private Access
Actions
Get Transport Rule
Gets information about a transport rule in an Exchange Online organization.
Installed version: 3.5.0
Parameters
Parameter | Description |
---|---|
Rule Name | Name of the existing transport rule to lookup. |
Example Output
{ "Priority": 0, "DlpPolicy": null, "DlpPolicyId": "00000000-0000-0000-0000-000000000000", "Comments": null, "CreatedBy": "User", "LastModifiedBy": "Microsoft Exchange", "ManuallyModified": false, "ActivationDate": null, "ExpiryDate": null, "Description": "If the message:\r\n\tsender's address domain portion belongs to any of these domains: 'blinkops.com' or 'example.com'\r\nTake the following actions:\r\n\tSet audit severity level to 'Low'\r\n\tand Prepend the message with the disclaimer 'this is from example.com!'. If the disclaimer can't be applied, take no action.\r\nExcept if the message:\r\n\tsender's address domain portion belongs to any of these domains: 'blinkops.com' or 'gmail.com' or 'random.com' or 'random.com' or 'random.com' or 'random2.com' or 'random12.com' or 'help.com' or 'shouldwork.com' or 'random1234.com'\r\n", "RuleVersion": { "Major": 15, "Minor": 0, "Build": 5, "Revision": 2, "MajorRevision": 0, "MinorRevision": 2 }, "Size": 815, "Conditions": [ "Microsoft.Exchange.MessagingPolicies.Rules.Tasks.SenderDomainIsPredicate" ], "Exceptions": [ "Microsoft.Exchange.MessagingPolicies.Rules.Tasks.SenderDomainIsPredicate" ], "Actions": [ "Microsoft.Exchange.MessagingPolicies.Rules.Tasks.SetAuditSeverityAction", "Microsoft.Exchange.MessagingPolicies.Rules.Tasks.ApplyHtmlDisclaimerAction" ], "State": "Disabled", "Mode": "Enforce", "RuleErrorAction": "Ignore", "SenderAddressLocation": "Header", "RecipientAddressType": "Resolved", "RuleSubType": "None", "RegexSize": 0, "UseLegacyRegex": false, "From": null, "FromMemberOf": null, "FromScope": null, "SentTo": null, "SentToMemberOf": null, "SentToScope": null, "BetweenMemberOf1": null, "BetweenMemberOf2": null, "ManagerAddresses": null, "ManagerForEvaluatedUser": null, "SenderManagementRelationship": null, "ADComparisonAttribute": null, "ADComparisonOperator": null, "SenderADAttributeContainsWords": null, "SenderADAttributeMatchesPatterns": null, "RecipientADAttributeContainsWords": null, "RecipientADAttributeMatchesPatterns": null, "AnyOfToHeader": null, "AnyOfToHeaderMemberOf": null, "AnyOfCcHeader": null, "AnyOfCcHeaderMemberOf": null, "AnyOfToCcHeader": null, "AnyOfToCcHeaderMemberOf": null, "HasClassification": null, "HasNoClassification": false, "SubjectContainsWords": null, "SubjectOrBodyContainsWords": null, "HeaderContainsMessageHeader": null, "HeaderContainsWords": null, "FromAddressContainsWords": null, "SenderDomainIs": [ "blinkops.com", "example.com" ], "RecipientDomainIs": null, "SubjectMatchesPatterns": null, "SubjectOrBodyMatchesPatterns": null, "HeaderMatchesMessageHeader": null, "HeaderMatchesPatterns": null, "FromAddressMatchesPatterns": null, "AttachmentNameMatchesPatterns": null, "AttachmentExtensionMatchesWords": null, "AttachmentPropertyContainsWords": null, "ContentCharacterSetContainsWords": null, "HasSenderOverride": false, "MessageContainsDataClassifications": null, "MessageContainsAllDataClassifications": null, "SenderIpRanges": null, "SCLOver": null, "AttachmentSizeOver": null, "MessageSizeOver": null, "WithImportance": null, "MessageTypeMatches": null, "RecipientAddressContainsWords": null, "RecipientAddressMatchesPatterns": null, "SenderInRecipientList": null, "RecipientInSenderList": null, "AttachmentContainsWords": null, "AttachmentMatchesPatterns": null, "AttachmentIsUnsupported": false, "AttachmentProcessingLimitExceeded": false, "AttachmentHasExecutableContent": false, "AttachmentIsPasswordProtected": false, "AnyOfRecipientAddressContainsWords": null, "AnyOfRecipientAddressMatchesPatterns": null, "ExceptIfFrom": null, "ExceptIfFromMemberOf": null, "ExceptIfFromScope": null, "ExceptIfSentTo": null, "ExceptIfSentToMemberOf": null, "ExceptIfSentToScope": null, "ExceptIfBetweenMemberOf1": null, "ExceptIfBetweenMemberOf2": null, "ExceptIfManagerAddresses": null, "ExceptIfManagerForEvaluatedUser": null, "ExceptIfSenderManagementRelationship": null, "ExceptIfADComparisonAttribute": null, "ExceptIfADComparisonOperator": null, "ExceptIfSenderADAttributeContainsWords": null, "ExceptIfSenderADAttributeMatchesPatterns": null, "ExceptIfRecipientADAttributeContainsWords": null, "ExceptIfRecipientADAttributeMatchesPatterns": null, "ExceptIfAnyOfToHeader": null, "ExceptIfAnyOfToHeaderMemberOf": null, "ExceptIfAnyOfCcHeader": null, "ExceptIfAnyOfCcHeaderMemberOf": null, "ExceptIfAnyOfToCcHeader": null, "ExceptIfAnyOfToCcHeaderMemberOf": null, "ExceptIfHasClassification": null, "ExceptIfHasNoClassification": false, "ExceptIfSubjectContainsWords": null, "ExceptIfSubjectOrBodyContainsWords": null, "ExceptIfHeaderContainsMessageHeader": null, "ExceptIfHeaderContainsWords": null, "ExceptIfFromAddressContainsWords": null, "ExceptIfSenderDomainIs": [ "blinkops.com", "gmail.com" ], "ExceptIfRecipientDomainIs": null, "ExceptIfSubjectMatchesPatterns": null, "ExceptIfSubjectOrBodyMatchesPatterns": null, "ExceptIfHeaderMatchesMessageHeader": null, "ExceptIfHeaderMatchesPatterns": null, "ExceptIfFromAddressMatchesPatterns": null, "ExceptIfAttachmentNameMatchesPatterns": null, "ExceptIfAttachmentExtensionMatchesWords": null, "ExceptIfAttachmentPropertyContainsWords": null, "ExceptIfContentCharacterSetContainsWords": null, "ExceptIfSCLOver": null, "ExceptIfAttachmentSizeOver": null, "ExceptIfMessageSizeOver": null, "ExceptIfWithImportance": null, "ExceptIfMessageTypeMatches": null, "ExceptIfRecipientAddressContainsWords": null, "ExceptIfRecipientAddressMatchesPatterns": null, "ExceptIfSenderInRecipientList": null, "ExceptIfRecipientInSenderList": null, "ExceptIfAttachmentContainsWords": null, "ExceptIfAttachmentMatchesPatterns": null, "ExceptIfAttachmentIsUnsupported": false, "ExceptIfAttachmentProcessingLimitExceeded": false, "ExceptIfAttachmentHasExecutableContent": false, "ExceptIfAttachmentIsPasswordProtected": false, "ExceptIfAnyOfRecipientAddressContainsWords": null, "ExceptIfAnyOfRecipientAddressMatchesPatterns": null, "ExceptIfHasSenderOverride": false, "ExceptIfMessageContainsDataClassifications": null, "ExceptIfMessageContainsAllDataClassifications": null, "ExceptIfSenderIpRanges": null, "PrependSubject": null, "SetAuditSeverity": "Low", "ApplyClassification": null, "ApplyHtmlDisclaimerLocation": "Prepend", "ApplyHtmlDisclaimerText": "this is from example.com!", "ApplyHtmlDisclaimerFallbackAction": "Ignore", "ApplyRightsProtectionTemplate": null, "ApplyRightsProtectionCustomizationTemplate": null, "SetSCL": null, "SetHeaderName": null, "SetHeaderValue": null, "RemoveHeader": null, "AddToRecipients": null, "CopyTo": null, "BlindCopyTo": null, "AddManagerAsRecipientType": null, "ModerateMessageByUser": null, "ModerateMessageByManager": false, "RedirectMessageTo": null, "RejectMessageEnhancedStatusCode": null, "RejectMessageReasonText": null, "DeleteMessage": false, "Disconnect": false, "Quarantine": false, "SmtpRejectMessageRejectText": null, "SmtpRejectMessageRejectStatusCode": null, "LogEventText": null, "StopRuleProcessing": false, "SenderNotificationType": null, "GenerateIncidentReport": null, "IncidentReportContent": null, "RouteMessageOutboundConnector": null, "RouteMessageOutboundRequireTls": false, "ApplyOME": false, "RemoveOME": false, "RemoveOMEv2": false, "RemoveRMSAttachmentEncryption": false, "GenerateNotification": null, "Identity": "Test", "DistinguishedName": "CN=testDC=PROD,DC=OUTLOOK,DC=COM", "Guid": "12345678-c51c-4945-94ce-e8485d24e8df", "ImmutableId": "12345678-c51c-4945-94ce-e8485d24e8df", "OrganizationId": "123456789", "Name": "Test", "IsValid": true, "WhenChanged": "2022-12-15T15:38:58+00:00", "ExchangeVersion": "0.1 (8.0.535.0)", "ObjectState": "Unchanged"}
Workflow Library Example
Get Transport Rule with Exchange Online and Send Results Via Slack
Preview this Automation on desktop
Was this page helpful?