Hi,
To build a KQL query or Condition Card builder for the specified criteria, you can try the following steps:
- Open the Microsoft 365 Compliance Center and navigate to the "Content search" page.
- Click on "Create a new search" and select "Specific locations" option.
- Select the mailbox of user1@domain.com as the source location.
- Select the "Advanced" option under the "Conditions" section.
- Enter the following KQL query in the search box: "from:user1@domain.com AND to:*@competitors.org AND received:02/01/2023..02/28/2023".
- Click "Save" to create the search and run it.
Alternatively, you can also use the Condition Card builder to build the same search by following these steps:
- Click on "Create a new search" in the "Content search" page.
- Select "Specific locations" and choose the mailbox of user1@domain.com.
- Under "Conditions", select "Add condition" and choose "Sent".
- Choose "Between" and select the date range from 1st February 2023 to 28th February 2023.
- Add another condition and choose "Sender".
- Enter "user1@domain.com" as the sender email address.
- Add one more condition and choose "Recipient".
- Enter "*.competitors.org" as the recipient email address.
- Click "Save" to create the search and run it.
These steps should help you build the KQL query or Condition Card builder to search for all emails from user1@domain.com to *@competitors.org between 1st February 2023 to 28th February 2023 in the Microsoft 365 Compliance Center.
Regards,
Bryce