We use Avanan for spam/phishing filtering. Avanan creates rules that Huntress does not like and triggers the following two alerts.
Transport Rules Should Not Bypass Security Controls
Connection Filter Should Not Bypass Spam Filtering
For the connection filter, I can accept the risk. I cannot do that for transport rules.
I'm not sure that "accept risk" is the best solution to this anyway. If we could review and approve the current config, but monitor for changes, maybe? Or Huntress might recognize the tenant is configured for Avanan (and other popular plug-in filters)?