Since BEC attacks target high profile users such as company executives, Cloud App Security allows you to add high profile users who are likely to be impersonated for detection and classification.
Specify the email display names and optionally email addresses of the high profile users who might be frequently impersonated. Cloud App Security uses the High Profile Users list for the following:
-
Check incoming email messages claimed to be sent from those users, apply fraud checking criteria to identify forged messages, and enable you to take action if BEC attacks are detected.
-
Allow you to directly take action when the display name of an external sender matches the list.
High Profile Users apply to all BEC detection technologies used by Cloud App Security. However, if you want to use writing style analysis to spot probable BEC attacks, you must specify the email address of a high profile user.
As a global setting, the specified high profile users are applicable to all Advanced Spam Protection enabled policies for your email service, that is, Exchange Online or Gmail, for BEC detection. For details, see Configuring Advanced Spam Protection.
Cloud App Security supports configuring a High Profile User Exception list to skip the scanning for BEC even when a sender's display name matches the High Profile Users list. For details, see Configuring High Profile User Exception List.