Evaluate Sophos EMS telemetry and recall emails with clawback
The Sophos Email Monitoring System (EMS) evaluates journal copies. Status values in Message History, including messages that appear to be quarantined, are therefore telemetry: they show what Sophos Email would have done to the message, not what happened to the original message that was already delivered. The original is removed from a supported Microsoft 365 mailbox only after a manual On-demand clawback succeeds.
Quick path: As a Super Admin, connect the affected Microsoft 365 domain from Global Settings > Products and Services > Email > Gateway Domains or M365 Mailflow Domains > Post-Delivery > Connect, grant Microsoft consent, and enable only On-demand clawback. Then find the delivered message in Reports > Email Security Logs > Message History, verify the recipient and subject, and select Initiate clawback. Verification is complete only when the status is Clawback Successful, the message appears under My Products > Email Security > Quarantined Messages > Post-delivery quarantine, and that same message is no longer in the selected recipient’s mailbox. The recipient, sender, and subject must match the values in Additional details and Post-delivery quarantine.
Important: EMS supports manual on-demand clawback only. Auto search and remediate is not part of the EMS operating model and is not activated for this flow. An EMS status Quarantined or Delivery Successful proves neither a real quarantine nor the actual delivery status of the original message.
Requirements and operating limits
The Super Admin role is required to set up and manage the post-delivery domain connection. The post-delivery functions are switched off by default. For the Microsoft-365 process described here, the following conditions must also be met:
- The Microsoft-365 gateway or mailflow domain already exists in Sophos Fusion.
- The browser allows the Microsoft pop-ups for authorization.
- You can sign in to the correct Microsoft-365 tenant and grant the requested Microsoft consent.
- The domain is individually linked for post-delivery protection; every connection requires Microsoft consent.
- The message to be withdrawn was successfully delivered to a mailbox in a connected domain.
On-demand clawback can move messages from one or more recipient mailboxes to post-delivery quarantine. In Microsoft 365, it can also include internally forwarded copies and replies. Mailboxes on the excluded mailboxes list are exempt from post-delivery actions; neither automatic nor manual clawback removes messages from them. Sophos allows up to five mailboxes on this exclusion list.
Access to Threat Analysis Center > Detections and Threat Analysis Center > Cases also requires Sophos EDR, XDR, or MDR. These licenses are not required to read an EMS report entry; they are required only for the downstream detection and case workflows.
Connect Microsoft 365 for manual clawback
- As Super Admin open Global Settings > Products and Services > Email.
- Select Gateway Domains or M365 Mailflow Domains. In the relevant row, hover over Post-Delivery status under Post-Delivery, then click Connect.
- If Sophos Fusion does not detect the email service automatically, select Microsoft M365 in the dialog. The process does not continue if the wrong service is selected.
- Read and accept the terms of use. This step is required for every newly connected domain.
- In the Microsoft pop-ups, verify the signed-in tenant and grant Sophos the requested permissions. Two consent prompts normally appear: one for the Sophos master application and one for API access. If a permission has already been granted, only one prompt may appear.
- After granting consent, click Continue. Establishing the connection may take a few minutes. When it is complete, select Close and check the domain’s connection status.
- Click Configure Post Delivery, enable On demand clawback, and select Save. Leave Auto search and remediate disabled for EMS.
Manage these features centrally in Global Settings > Products and Services > Email > Post Delivery Protection. Include internally forwarded emails extends manual clawback to the original message and to internally forwarded copies or replies, including copies in Inbox and Sent Items. Enable this option only when the wider scope is intended; it is supported only for Microsoft 365 mailboxes.
If a sensitive mailbox must not be subject to post-delivery actions, enable Exclude mailboxes and add it to excluded mailboxes. Before saving, be aware that a later manual clawback will not remove messages from that mailbox.
Read EMS telemetry correctly
The main view is at Reports > Email Security Logs > Message History; depending on the navigation, it is also available through My Products > Email Security > Reports > Message History. The Processed report shows one row for each processed message, even when a message has multiple recipients. The columns are:
- Direction: incoming or outgoing;
- Sender and Recipients: sender and all recipients;
- Type: Gateway or Mailflow;
- Subject: opens the message details;
- Last Status: recent activity in the report;
- Date: date of this most recent activity;
- Category: classification of the message.
The report separates successfully processed messages under Processed from messages rejected because a mailbox was not found under Rejected. For gateway and mailflow domains, use Type to narrow the results to the required source. The current day is shown by default; after changing the date range or filters, select Refresh to update the view.
In EMS mode, Last Status, Category, and delivery values describe Sophos’s assessment of the scanned journal copy. Do not treat Quarantined, Deleted, or Delivery Successful as evidence that an action occurred on the original message. The same boundary is visible in My Products > Email Security > Quarantined Messages: an EMS entry with the simulated status Quarantined does not contain the original message. Messages that were actually withdrawn appear in Post-delivery quarantine.
Withdraw a message in a controlled manner
Before taking action, narrow the results using Direction, Sender, Recipients, Subject, Date, and Category. Only successfully delivered inbound messages are eligible for clawback. Because one row can contain several recipients, check the recipient list carefully before confirming.
Clawback for entire messages from Message History
- In Reports > Email Security Logs > Message History, filter for inbound messages that were delivered successfully. Use Advanced Search to narrow the selection further.
- Select the required messages. Select all applies only to the current page, so recheck the filters and visible results before continuing.
- Click on Initiate clawback.
- Optionally select Spam emails, Malware emails, Phishing emails, or Unwanted emails as the reason. For spam, malware, or phishing, you can also submit the message by selecting Report the emails to SophosLabs.
- Select Confirm to start the clawback.
Limit clawback to specific recipients
- Open Reports > Email Security Logs > Message History > Processed and click on the Subject of the message.
- In the message details, only select the affected Recipients.
- To remove internal forwards or replies as well, select the relevant recipients in the Internal forwards table. Otherwise, the scope remains limited to the selected original recipients.
- Click on Initiate clawback, select the reason and, if necessary, Report the emails to SophosLabs.
- Confirm the action with Clawback. The detailed status appears in Additional details.
A clawback can take up to ten minutes. External mailboxes may appear in the results, but post-delivery actions work only for mailboxes in domains connected to Sophos Fusion. A message and any internally forwarded copies or replies can be withdrawn only once. If the message is later released from post-delivery quarantine, it cannot be removed again with clawback.
Validate result
Successful validation checks both sides of the action:
- In Message History or Additional details, the process changes from Clawback Initiated to Clawback Successful. Clawback Failed is not a partial success; Clawback Released means the request has been canceled or the message has been released.
- Under My Products > Email Security > Quarantined Messages, the message appears in Post-delivery quarantine. There, compare quarantine source, status, sender, recipient and subject with the original incident.
- For a controlled test, check one selected Microsoft 365 recipient mailbox and confirm that the exact message is no longer present. Recipient, sender, and subject must match Additional details and the entry in Post-delivery quarantine. If the message remains in the selected mailbox or cannot be matched unambiguously, validation has failed. Next, check the selected recipient, the connected domain, excluded mailboxes, and Additional details.
- If specific recipients were selected, confirm that only those recipients were processed. For distribution lists, the status may remain Clawback Initiated even after a successful attempt.
The post-delivery quarantine therefore contains the truly withdrawn message. Other EMS entries with Quarantined remain simulated judgments and do not subsequently become real quarantine objects.
Hand over findings to Detections and Cases
If you choose a reason for clawback, a detection is sent to MDR; the reason appears as a suffix in the Detection Rule column. This handoff is separate from the EMS report statuses. A simulated EMS quarantine does not automatically create either a detection or a case.
With EDR, XDR, or MDR, open Threat Analysis Center > Detections and filter by Severity, detection type, time range, and device/entity. A detection is created only when suitable telemetry has been uploaded to the Sophos Data Lake and matches a detection rule. A missing entry therefore does not prove that the EMS report entry is incorrect.
Under Threat Analysis Center > Cases, review Severity, Status, Managed by, assignee, and the associated detections. The MDR team investigates MDR-based cases managed by Sophos. Sophos does not investigate XDR cases marked Managed by: Self; assign them to an administrator for internal investigation. An empty case list on first access can be normal.
Troubleshoot by symptom
Microsoft prompt does not appear: Disable the pop-up blocker for Microsoft 365 domains or add an exception, then start Connect again. Post-Delivery Protection does not work until the permissions are granted.
Wrong Microsoft tenant opens: Do not confirm the saved credentials. Close the connection dialog and start again in a private browser window with the correct tenant.
Sophos does not recognize the service: Select Microsoft M365 in the service-selection dialog. If no dialog appears or the domain does not match the Microsoft tenant, do not proceed by authorizing a different or unrelated tenant or account.
Connection fails: Check whether the message reports a timeout, missing consent for API or data access, or mismatched domains. Correct the cause before reconnecting. If the message gives no reason, escalate the error to Sophos or the Microsoft 365 administrators; do not change permissions or domains without a confirmed cause.
Message shows Quarantined, but is still in the mailbox: In EMS mode this is to be expected as long as no successful manual clawback has taken place. First check whether the entry only shows the simulated judgment of a journal copy.
Clawback missing or failing: Check that On demand clawback is enabled, the inbound message was delivered successfully, and the target mailbox belongs to a connected domain and is not listed under excluded mailboxes. Then check Additional details and the domain’s Post-Delivery status. Do not start the action more than once during the documented ten-minute period.
No detections or cases: First check the additional EDR, XDR or MDR authorization. Detections require uploaded, appropriate data lake telemetry and a detection rule match. For cases, an initially empty list can be normal; XDR cases also remain self-managed.
Safe rollback and ongoing operations
If the manual clawback is no longer to be offered, open Global Settings > Products and Services > Email > Post Delivery Protection, switch off On demand clawback and save with Save. Then check that the function is deactivated. Messages that have already been withdrawn will not be automatically released.
To decommission the connection completely, first check the affected domain, its Post-Delivery status, and any clawback operations in progress. Then use the domain’s Disconnect action in Gateway Domains or M365 Mailflow Domains. Sophos does not document any further automatic cleanup in the Microsoft tenant. If the domain still does not show as disconnected afterward, or if the Microsoft permissions must be removed separately, stop and confirm the next step with Sophos or the Microsoft 365 administrators rather than deleting permissions speculatively.
For routine operation, use a short, repeatable check: review new EMS assessments in Message History, keep simulated and real quarantine strictly separate, track open Clawback Initiated or Clawback Failed operations, and assign self-managed XDR cases to an assignee. Before making changes, also verify that the required licenses are available in the tenant and that the planned procedure still matches the current Sophos product documentation.
Related Guide
EMS monitors messages, but it does not secure your own sender domains. For the separate tasks of report delivery, SPF/DKIM alignment, and gradual policy enforcement, see Set up Sophos Email DMARC Manager.