High-confidence phishing delivered to Inbox/Junk without policy override
This rule detects high-confidence phishing emails that were delivered to either the Inbox or Junk folder. It explicitly filters out messages that have been explicitly allowed by organization-level policies, user-level actions, or specific safe-sender bypass mechanisms, ensuring the alert focuses on malicious emails that bypassed standard security filters without an authorized exception.
Microsoft Sentinel (KQL)

