The Approved Header Field List for Exchange Online specifies the header field criteria for email messages in Exchange Online to bypass policy scanning when a message matches any of the criteria.
Cloud App Security allows you to set up approved email header field lists in policies and in administrative settings for different purposes. If you want certain email messages to skip scanning by all policies, for example, to do a phishing simulation campaign via email, you can create a global approved list so messages that match the header field criteria will not be scanned by all enabled Advanced Threat Protection and Data Loss Prevention policies for Exchange Online and will be delivered to the intended recipients.
For more information about how to configure an approved header field list that applies only to the ATP policy where it is configured, see the Configuring Advanced Spam Protection and Configuring Web Reputation sections in Chapter Advanced Threat Protection.