Yesterday my company was hit with a new trojan that uses the old social method of "it came from someone I trust" to suspend user's suspicion (and rationality) and it was opened and run.
During the course of finding, containing, and eliminating this thing I used the Exchange Online (Office365) Transport Rules to block all outgoing email from the infected users (and send me the blocked message). After I was sure that the bug was squished I unchecked the Transport Rules, but found that the users still could not send. Then I Deleted the Transport Rules, and tested with one user, and some went through, while some got blocked.
I used Powershell to log in and Get-TransportRule does not show the rules that are still (occasionally, randomly) blocking these users after a half-hour.
How long is it supposed to take? How long until I start a ticket process? Or did I miss something?