Quarantined email messages - Microsoft Defender for Office 365 (2024)

  • Article
  • Applies to:
    Exchange Online Protection, ✅ Microsoft Defender for Office 365 Plan 1 and Plan 2, ✅ Microsoft Defender XDR

Tip

Did you know you can try the features in Microsoft Defender XDR for Office 365 Plan 2 for free? Use the 90-day Defender for Office 365 trial at the Microsoft Defender portal trials hub. Learn about who can sign up and trial terms on Try Microsoft Defender for Office 365.

In Microsoft 365 organizations with mailboxes in Exchange Online or standalone Exchange Online Protection (EOP) organizations without Exchange Online mailboxes, quarantine is available to hold potentially dangerous or unwanted messages.

Note

In Microsoft 365 operated by 21Vianet, quarantine isn't currently available in the Microsoft Defender portal. Quarantine is available only in the classic Exchange admin center (classic EAC).

Whether a detected message is quarantined by default depends on the following factors:

  • The protection feature that detected the message. For example, the following detections are always quarantined:
    • Malware detections by anti-malware policies and Safe Attachments policies, including Built-in protection for Safe Attachments*.
    • High confidence phishing detections by anti-spam policies.
  • Whether you're using the Standard and/or Strict preset security policies. The Strict profile quarantines more types of detections than the Standard profile.

* Malware filtering is skipped on SecOps mailboxes that are identified in the advanced delivery policy. For more information, see Configure the advanced delivery policy for third-party phishing simulations and email delivery to SecOps mailboxes.

The default actions for protection features in EOP and Defender for Office 365, including preset security policies, are described in the feature tables in Recommended settings for EOP and Microsoft Defender for Office 365 security.

For anti-spam and anti-phishing protection, admins can also modify the default policy or create custom policies to quarantine messages instead of delivering them to the Junk Email folder. For instructions, see the following articles:

  • Configure anti-spam policies in EOP
  • Configure anti-phishing policies in EOP
  • Configure anti-phishing policies in Microsoft Defender for Office 365

The protection policies for supported features have one or more quarantine policies assigned to them (each action within the protection policy has an associated quarantine policy assignment).

Tip

All actions taken by admins or users on quarantined messages are audited. For more information about audited quarantine events, see Quarantine schema in the Office 365 Management API.

Quarantine policies

Quarantine policies define what users are able to do or not do to quarantined messages, and whether users receive quarantine notifications for those messages. For more information, see Anatomy of a quarantine policy.

Tip

You can create customized quarantine notifications for different languages. You can also use a custom logo in quarantine notifications.

The default quarantine policies that are assigned to protection feature verdicts enforce the historical capabilities that users get for their quarantined messages (messages where they're a recipient). For more information, see the table in Find and release quarantined messages as a user in EOP. For example, only admins can work with messages that were quarantined as malware or high confidence phishing. By default, users can work with their messages that were quarantined as spam, bulk, phishing, spoof, user impersonation, domain impersonation, or mailbox intelligence.

Admins can create and apply custom quarantine policies that define less restrictive or more restrictive capabilities for users, and also turn on quarantine notifications. For more information, see Create quarantine policies.

Note

Users can't release their own messages that were quarantined as malware by anti-malware or Safe Attachments policies, or as high confidence phishing by anti-spam policies, regardless of how the quarantine policy is configured. If the policy allows users to release their own quarantined messages, users are instead allowed to request the release of their quarantined malware or high confidence phishing messages.

Both users and admins can work with quarantined messages:

  • Admins can work with all types of quarantined messages for all users, including messages that were quarantined as malware, high confidence phishing, or as a result of mail flow rules (also known as transport rules). For more information, see Manage quarantined messages and files as an admin in EOP.

    Tip

    For the permissions required to download and release any messages from quarantine, see the permissions entry here.

  • Users can work with their quarantined messages based on the protection feature that quarantined the message, and the setting in corresponding quarantine policy. For more information, see Find and release quarantined messages as a user in EOP.

  • Admins can report false positives to Microsoft from quarantine. For more information, see Take action on quarantined email and Take action on quarantined files.

  • Users can also report false positives to Microsoft from quarantine, depending on the value of the Reporting from quarantine setting in user reported settings.

Quarantine retention

How long quarantined messages or files are held in quarantine before they expire depends why the message or file was quarantined. Features and their corresponding retention periods are described in the following table:

Quarantine reasonDefault retention periodCustomizable?Comments
Messages quarantined by anti-spam policies as spam, high confidence spam, phishing, high confidence phishing, or bulk.15 days
  • In the default anti-spam policy.
  • In anti-spam policies that you create in PowerShell.

30 days
  • In anti-spam policies that you create in the Microsoft Defender portal.
  • In the Standard and Strict preset security policies
Yes*You can configure the value from 1 to 30 days in the default anti-spam policy and in custom anti-spam policies. For more information, see the Retain spam in quarantine for this many days (QuarantineRetentionPeriod) setting in Configure anti-spam policies.

*You can't change the value in the Standard or Strict preset security policies.

Messages quarantined by anti-phishing policies:
  • EOP: Spoof intelligence.
  • Defender for Office 365: User impersonation protection, domain impersonation protection, and mailbox intelligence protection.
15 days or 30 daysYes*This retention period is also controlled by the Retain spam in quarantine for this many days (QuarantineRetentionPeriod) setting in anti-spam policies. The retention period that's used is the value from the first matching anti-spam policy that the recipient is defined in.
Messages quarantined by anti-malware policies (malware messages).30 daysNoIf you turn on the common attachments filter in anti-malware policies (in the default policy or in custom policies), file attachments in email messages to the affected recipients are treated as malware based solely on the file extension using true type matching. A predefined list of mostly executable file types is used by default, but you can customize the list. For more information, see Common attachments filter in anti-malware policies.
Messages quarantined by mail flow rules where the action is Deliver the message to the hosted quarantine (Quarantine).30 daysNo
Messages quarantined by Safe Attachments policies in Defender for Office 365 (malware messages).30 daysNo
Files quarantined by Safe Attachments for SharePoint, OneDrive, and Microsoft Teams (malware files).30 daysNoFiles quarantined in SharePoint or OneDrive are removed from quarantine after 30 days, but the blocked files remain in SharePoint or OneDrive in the blocked state.
Messages in chats and channels quarantined by zero-hour auto protection (ZAP) for Microsoft Teams in Defender for Office 36530 daysNo

When a message expires from quarantine, you can't recover it.

For more information about quarantine, see Quarantine FAQ.

Quarantined email messages - Microsoft Defender for Office 365 (2024)
Top Articles
The Essential Guide to Japan VPN for Travelers - Events Hakuba
Green Infrastructure: How to Manage Water in a Sustainable Way
Funny Roblox Id Codes 2023
Matgyn
It's Official: Sabrina Carpenter's Bangs Are Taking Over TikTok
Obor Guide Osrs
Body Rubs Austin Texas
DENVER Überwachungskamera IOC-221, IP, WLAN, außen | 580950
Nm Remote Access
Newgate Honda
Morocco Forum Tripadvisor
Bestellung Ahrefs
Oro probablemente a duna Playa e nomber Oranjestad un 200 aña pasa, pero Playa su historia ta bay hopi mas aña atras
Rainfall Map Oklahoma
Craigslist Free Stuff Greensboro Nc
Puretalkusa.com/Amac
Craigslist Red Wing Mn
Aspen Mobile Login Help
H12 Weidian
Curry Ford Accident Today
Theater X Orange Heights Florida
Gazette Obituary Colorado Springs
11 Ways to Sell a Car on Craigslist - wikiHow
Reviews over Supersaver - Opiness - Spreekt uit ervaring
Horn Rank
Leben in Japan – das muss man wissen - Lernen Sie Sprachen online bei italki
Movies - EPIC Theatres
Login.castlebranch.com
Www.1Tamilmv.con
Little Einsteins Transcript
Tenant Vs. Occupant: Is There Really A Difference Between Them?
Crystal Mcbooty
Are you ready for some football? Zag Alum Justin Lange Forges Career in NFL
Babylon 2022 Showtimes Near Cinemark Downey And Xd
The Thing About ‘Dateline’
Express Employment Sign In
Flipper Zero Delivery Time
Seminary.churchofjesuschrist.org
Kb Home The Overlook At Medio Creek
Powerboat P1 Unveils 2024 P1 Offshore And Class 1 Race Calendar
Shell Gas Stations Prices
Dickdrainersx Jessica Marie
Patricia And Aaron Toro
Avatar: The Way Of Water Showtimes Near Jasper 8 Theatres
Senior Houses For Sale Near Me
Stitch And Angel Tattoo Black And White
Muni Metro Schedule
Used Auto Parts in Houston 77013 | LKQ Pick Your Part
Gear Bicycle Sales Butler Pa
Publix Store 840
Ingersoll Greenwood Funeral Home Obituaries
Provincial Freeman (Toronto and Chatham, ON: Mary Ann Shadd Cary (October 9, 1823 – June 5, 1893)), November 3, 1855, p. 1
Latest Posts
Article information

Author: Rob Wisoky

Last Updated:

Views: 5788

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Rob Wisoky

Birthday: 1994-09-30

Address: 5789 Michel Vista, West Domenic, OR 80464-9452

Phone: +97313824072371

Job: Education Orchestrator

Hobby: Lockpicking, Crocheting, Baton twirling, Video gaming, Jogging, Whittling, Model building

Introduction: My name is Rob Wisoky, I am a smiling, helpful, encouraging, zealous, energetic, faithful, fantastic person who loves writing and wants to share my knowledge and understanding with you.