Fortinet white logo
Fortinet white logo

CLI Reference

cloud-api profile action

cloud-api profile action

Use this command to apply specific actions the FortiMail system takes when encountering an infected email during a scan through an HTTPS cloud API connection to mailboxes. The actions applied on Microsoft 365 and Google Workspace are different from those applied during SMTP scans on the FortiMail system itself.

Syntax

config cloud-api profile action

edit <profile_name>

[set comment "<comment_str>"]

set archive-status {enable | disable}

set archive-account <account_name>

set final-action {discard | move | none | personal-quarantine | system-quarantine}

set notification-status {enable | disable}

set notification-profile <profile_name>

set move-to-folder-name <path_str>

set replace-status {enable | disable}

set replace-message <replacement-message_name>

end

Variable

Description

Default

<profile_name>

Enter a unique name for the profile.

archive-account <account_name>

Select which email archive account to use.

This setting is used only if archive-status {enable | disable} is enabled.

archive-status {enable | disable}

Enable or disable email archiving. Also configure archive-account <account_name>.

disable

comment "<comment_str>"

Enter a description or comment.

final-action {discard | move | none | personal-quarantine | system-quarantine}

Select which action to perform if the email violates a scan in the policy:

  • discard: Delete the email message from the user’s inbox on Microsoft 365, Microsoft Exchange, or Google Workspace.

  • move: Move the email message to a specified folder on Microsoft 365, Microsoft Exchange, or Google Workspace. Also configure move-to-folder-name <path_str>.

  • none: No action.

  • personal-quarantine: Move the email message to the user's junk folder on Microsoft 365 or Microsoft Exchange, or to the spam folder on Google Workspace.

  • system-quarantine: Move the email to the FortiMail system quarantine. Also configure system-quarantine-release-original {enable | disable}.

move-to-folder-name <path_str>

Enter the name of the folder that the email messages should be moved to.

This setting is used only when final-action {discard | move | none | personal-quarantine | system-quarantine} is move.

notification-profile <profile_name>

Select which notification profile to use to specify the notification recipients.

This setting is used only if notification-status {enable | disable} is enabled.

notification-status {enable | disable}

Enable to send notifications to the recipients specified in the notification profile when a FortiMail scan performs an action such as discard or quarantine. Also configure notification-profile <profile_name>.

disable

replace-message <replacement-message_name>

Select which replacement message to use.

This setting is used only if replace-status {enable | disable} is enabled.

default

replace-status {enable | disable}

Enable to replace the email attachment with a custom message when the content or antivirus scan detects an infection or content policy violation. Also configure replace-message <replacement-message_name>.

disable

Related topics

cloud-api profile antispam

cloud-api profile antivirus

cloud-api profile content

cloud-api profile dlp

cloud-api profile weighted-analysis

archive account

cloud-api profile action

cloud-api profile action

Use this command to apply specific actions the FortiMail system takes when encountering an infected email during a scan through an HTTPS cloud API connection to mailboxes. The actions applied on Microsoft 365 and Google Workspace are different from those applied during SMTP scans on the FortiMail system itself.

Syntax

config cloud-api profile action

edit <profile_name>

[set comment "<comment_str>"]

set archive-status {enable | disable}

set archive-account <account_name>

set final-action {discard | move | none | personal-quarantine | system-quarantine}

set notification-status {enable | disable}

set notification-profile <profile_name>

set move-to-folder-name <path_str>

set replace-status {enable | disable}

set replace-message <replacement-message_name>

end

Variable

Description

Default

<profile_name>

Enter a unique name for the profile.

archive-account <account_name>

Select which email archive account to use.

This setting is used only if archive-status {enable | disable} is enabled.

archive-status {enable | disable}

Enable or disable email archiving. Also configure archive-account <account_name>.

disable

comment "<comment_str>"

Enter a description or comment.

final-action {discard | move | none | personal-quarantine | system-quarantine}

Select which action to perform if the email violates a scan in the policy:

  • discard: Delete the email message from the user’s inbox on Microsoft 365, Microsoft Exchange, or Google Workspace.

  • move: Move the email message to a specified folder on Microsoft 365, Microsoft Exchange, or Google Workspace. Also configure move-to-folder-name <path_str>.

  • none: No action.

  • personal-quarantine: Move the email message to the user's junk folder on Microsoft 365 or Microsoft Exchange, or to the spam folder on Google Workspace.

  • system-quarantine: Move the email to the FortiMail system quarantine. Also configure system-quarantine-release-original {enable | disable}.

move-to-folder-name <path_str>

Enter the name of the folder that the email messages should be moved to.

This setting is used only when final-action {discard | move | none | personal-quarantine | system-quarantine} is move.

notification-profile <profile_name>

Select which notification profile to use to specify the notification recipients.

This setting is used only if notification-status {enable | disable} is enabled.

notification-status {enable | disable}

Enable to send notifications to the recipients specified in the notification profile when a FortiMail scan performs an action such as discard or quarantine. Also configure notification-profile <profile_name>.

disable

replace-message <replacement-message_name>

Select which replacement message to use.

This setting is used only if replace-status {enable | disable} is enabled.

default

replace-status {enable | disable}

Enable to replace the email attachment with a custom message when the content or antivirus scan detects an infection or content policy violation. Also configure replace-message <replacement-message_name>.

disable

Related topics

cloud-api profile antispam

cloud-api profile antivirus

cloud-api profile content

cloud-api profile dlp

cloud-api profile weighted-analysis

archive account