Is anyone else seeing a large amount of M365 internal tenant email being quarantined as "high confidence phish". By internal I mean messages from one user to another in the same tenant and on the same local LAN. DNS, DKIM, and DMARC are in order and nothing has changed on the tenant configuration. Looking at the quarantine, it appears to have started as early as yesterday but really picked up today. It is multiple senders in the same local M365 tenant.
Source: r/sysadmin · by /u/youreensample