Quarantine policies in Microsoft Defender for Office 365 and Exchange Online Protection decide two things for each type of detection: what recipients can do with their own quarantined messages (nothing, request release, or release) and whether they receive quarantine notifications. To change the defaults, create a custom quarantine policy in the Defender portal under Email & collaboration > Policies & rules > Threat policies > Quarantine policies, assign it to the verdict in your anti-spam, anti-phishing, anti-malware or Safe Attachments policy, and set the notification frequency and branding in Global settings. Malware and high confidence phishing can never be released by users themselves, only requested.
Who this is for and what you will have
This guide is for Microsoft 365 administrators who want to reduce help desk tickets about quarantined mail without letting users release dangerous messages. It applies to all organizations with cloud mailboxes; impersonation detections and Safe Attachments need Defender for Office 365. At the end you will have:
- A quarantine policy design that matches each verdict to the right level of user access.
- Custom policies created in the portal or in PowerShell.
- Those policies assigned to your threat policies, with quarantine notifications turned on where you want them.
- A process for reviewing release requests as an admin.
How quarantine policies work
Permission groups
A quarantine policy contains individual permissions, grouped into three presets:
| Permission | No access | Limited access | Full access |
|---|---|---|---|
| View message header | Yes | Yes | Yes |
| Allow sender | No | Yes | Yes |
| Delete | No | Yes | Yes |
| Preview | No | Yes | Yes |
| Release a message from quarantine | No | No | Yes |
| Request release of a message | No | Yes | No |
With No access and notifications off, users don't see the messages at all. With No access and notifications on, users see their messages and get notifications, but the only action is View message headers (in quarantine) or Review message (in the notification). That combination is useful when you want users to know something was held without letting them act on it.
Default quarantine policies
Microsoft provides default policies whose settings are read-only:
| Default policy | Permission group | Notifications |
|---|---|---|
| AdminOnlyAccessPolicy | No access | Off |
| DefaultFullAccessPolicy | Full access | Off |
| DefaultFullAccessWithNotificationPolicy | Full access | On |
| NotificationEnabledPolicy | Full access | On |
NotificationEnabledPolicy only exists in organizations that existed before quarantine policies were introduced in July-August 2021 and had end-user spam notifications turned on. You can't delete AdminOnlyAccessPolicy, DefaultFullAccessPolicy or DefaultFullAccessWithNotificationPolicy.
Which policy each verdict uses
These are the default and preset assignments from Microsoft's recommended settings:
| Verdict | Default policy | Standard preset | Strict preset |
|---|---|---|---|
| Spam | DefaultFullAccessPolicy | DefaultFullAccessPolicy | DefaultFullAccessWithNotificationPolicy |
| High confidence spam | DefaultFullAccessPolicy | DefaultFullAccessWithNotificationPolicy | DefaultFullAccessWithNotificationPolicy |
| Phishing | DefaultFullAccessPolicy | DefaultFullAccessWithNotificationPolicy | DefaultFullAccessWithNotificationPolicy |
| High confidence phishing | AdminOnlyAccessPolicy | AdminOnlyAccessPolicy | AdminOnlyAccessPolicy |
| Bulk | DefaultFullAccessPolicy | DefaultFullAccessPolicy | DefaultFullAccessWithNotificationPolicy |
| Spoof | DefaultFullAccessPolicy | DefaultFullAccessPolicy | DefaultFullAccessWithNotificationPolicy |
| Malware (anti-malware) | AdminOnlyAccessPolicy | AdminOnlyAccessPolicy | AdminOnlyAccessPolicy |
| Safe Attachments | AdminOnlyAccessPolicy | AdminOnlyAccessPolicy | AdminOnlyAccessPolicy |
A quarantine policy only matters when the verdict's action is to quarantine. By default, for example, spoof detections go to Junk Email in the default and Standard settings, so the spoof quarantine policy has no effect until you change the action.
What users can never release
Regardless of the quarantine policy, recipients can't release:
- Messages quarantined as malware by anti-malware policies.
- Messages quarantined as malware or phishing by Safe Attachments policies.
- Messages quarantined as high confidence phishing by anti-spam policies.
If the policy grants release permission for these, users can only request release. Messages quarantined by mail flow rules with the action Deliver the message to the hosted quarantine don't support quarantine policies at all; admins manage those messages.
Prerequisites
- Membership in the Quarantine Administrator, Security Administrator or Organization Management role group in the Defender portal, or the Security Administrator role in Microsoft Entra ID. If Defender XDR Unified RBAC is active for email and collaboration, the permission is Authorization and settings/Security settings/Core Security settings (manage) or Security operations/Security Data/Email & collaboration quarantine (manage).
- Roles assigned through Privileged Identity Management aren't currently supported in quarantine, so use a permanent assignment for the admins who manage it.
- Exchange Online PowerShell for the scripted steps.
- An inventory of your threat policies, so you know where each quarantine policy will be assigned.
Step 1: Create a custom quarantine policy
A common design is to keep spam on Full access, but move phishing to Limited access with notifications, so users can see and request release of a suspected phishing message while an admin makes the final decision.
In the Defender portal
- In the Microsoft Defender portal, go to Email & collaboration > Policies & rules > Threat policies > Quarantine policy in the Rules section, or open
https://security.microsoft.com/quarantinePolicies. - Select Add custom policy.
- On Policy name, enter a unique name such as
Phish-LimitedWithNotify. You can't rename a policy later. - On Recipient message access, select Limited access. Or select Set specific access (Advanced) and choose a release action (blank, Allow recipients to request a message to be released from quarantine or Allow recipients to release a message from quarantine) plus any of Delete, Preview, Block sender and Allow sender.
- On Quarantine notification, select Enable, then choose whether to include messages quarantined from blocked sender addresses. If you exclude them, recipients aren't notified about messages quarantined for blocked senders or bulk detections.
- Review and select Submit.
In PowerShell
New-QuarantinePolicy takes the permissions as a single decimal number built from these bits:
| Permission | Decimal value |
|---|---|
| PermissionToViewHeader | 128 |
| PermissionToDownload (not used) | 64 |
| PermissionToAllowSender | 32 |
| PermissionToBlockSender | 16 |
| PermissionToRequestRelease | 8 |
| PermissionToRelease | 4 |
| PermissionToPreview | 2 |
| PermissionToDelete | 1 |
Add the values of the permissions you want. Never set both PermissionToRequestRelease and PermissionToRelease. Limited access is 32 + 8 + 2 + 1 = 43:
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
New-QuarantinePolicy -Name "Phish-LimitedWithNotify" -EndUserQuarantinePermissionsValue 43 -EsnEnabled $trueA "notify only" policy uses 0 with notifications on, so users see the message and its headers but can't act on it:
New-QuarantinePolicy -Name "NotifyOnly-NoAccess" -EndUserQuarantinePermissionsValue 0 -EsnEnabled $trueEsnEnabled defaults to $false, so leave it out only when you want no notifications.
Step 2: Assign the policy to threat policies
Each verdict that quarantines has its own quarantine policy setting.
Anti-spam policies
In the portal, open Threat policies > Anti-spam, select an inbound policy, select Edit actions, and choose the policy in Select quarantine policy next to each verdict set to Quarantine message. In PowerShell:
Set-HostedContentFilterPolicy -Identity "Human Resources" -PhishSpamAction Quarantine -PhishQuarantineTag "Phish-LimitedWithNotify"
Get-HostedContentFilterPolicy | Format-List Name,SpamAction,SpamQuarantineTag,PhishSpamAction,PhishQuarantineTag,HighConfidencePhishQuarantineTag,BulkQuarantineTagThe anti-spam policy's Retain spam in quarantine for this many days setting (QuarantineRetentionPeriod) also controls retention for anti-phishing quarantine. It defaults to 15 days in the default and custom policies and can be set from 1 to 30 days; the Standard and Strict presets use 30 days.
Anti-phishing, anti-malware and Safe Attachments
- Anti-phishing: on the Actions page, each verdict set to Quarantine the message has an Apply quarantine policy box. The PowerShell parameters are
SpoofQuarantineTag,TargetedUserQuarantineTag,TargetedDomainQuarantineTagandMailboxIntelligenceQuarantineTagonSet-AntiPhishPolicy. - Anti-malware: the Quarantine policy box on Protection settings, or
Set-MalwareFilterPolicy -QuarantineTag. Use a policy with notifications on if you want recipients told about malware detections; they still can't release them. - Safe Attachments:
Set-SafeAttachmentPolicy -QuarantineTagfor detections, andQuarantineTagForBlockingEncryptedAttachmentsfor password-protected attachments that couldn't be scanned (DefaultFullAccessWithNotificationPolicy by default).
A changed assignment only applies to messages quarantined after the change. Messages already in quarantine keep the policy they were quarantined with.
Step 3: Configure quarantine notifications globally
Open Quarantine policies and select Global settings. The settings apply to every policy with notifications turned on:
- Specify sender address: an existing internal user. The default sender is
quarantine@messaging.microsoft.com. - Use my company logo: uses the logo from your Microsoft 365 organization theme. PNG and JPEG logos are the most compatible across Outlook versions.
- Send end-user spam notification every (days): Within 4 hours, Daily or Weekly.
- Language-specific Sender display name, Subject and Disclaimer (up to 200 characters), for up to three languages. Select the language first, because values entered before choosing a language are cleared.
The PowerShell equivalent targets the global policy:
Get-QuarantinePolicy -QuarantinePolicyType GlobalQuarantinePolicy |
Set-QuarantinePolicy -EndUserSpamNotificationFrequency 1.00:00:00 -OrganizationBrandingEnabled $true `
-MultiLanguageSetting ('Default') -ESNCustomSubject ('You have quarantined messages') `
-MultiLanguageSenderName ('Contoso Mail Security') `
-MultiLanguageCustomDisclaimer ('Questions? Contact the service desk.')Quarantine notifications aren't localized for on-premises mailboxes.
Step 4: Review and release as an admin
Admins see all quarantined messages, including malware, high confidence phishing and mail flow rule detections, at Email & collaboration > Review > Quarantine (https://security.microsoft.com/quarantine). Filter by Release status (Needs review, Release requested, Denied, Released), Policy type or quarantine reason.
When a user requests release, the status changes to Release requested and the built-in alert policy User requested to release a quarantined message notifies admins. Audit logging must be on for that alert, which it is by default. To act on a request:
- Select Release (or Release email in the details flyout) to approve. You can send a copy to other recipients and, as a Security Administrator, submit the message to Microsoft as a false positive with an optional Tenant Allow/Block List allow entry.
- Select Deny (or More > Deny release). Denial applies to all recipients of the message.
You can select up to 100 messages for bulk actions. In PowerShell:
Get-QuarantineMessage -MessageID "<5c695d7e-6642-4681-a4b0-9e7a86613cb7@contoso.com>" |
Release-QuarantineMessage -User julia@contoso.comUse -ReleaseToAll instead of -User to release to every original recipient; recipients who already received a released copy are skipped. When you need to understand why a message never arrived after release, trace it as described in message trace with Get-MessageTraceV2.
Verify the configuration
- Run
Get-QuarantinePolicy | Format-Table Nameand confirm your custom policies exist. - Run the
Get-HostedContentFilterPolicy,Get-AntiPhishPolicy,Get-MalwareFilterPolicyandGet-SafeAttachmentPolicycommands with their*QuarantineTagproperties and confirm each verdict uses the intended policy. - Wait for a real detection, or review the Quarantine page for a recent message, and confirm the recipient sees the actions you expect.
- Confirm a test user receives a notification on the schedule you set.
Troubleshooting
Users don't receive notifications. The verdict uses a policy with notifications off, or the message was quarantined before you changed the assignment. Also check the frequency in Global settings: with Daily or Weekly, notifications arrive only on that schedule.
Admins see PermissionToRelease as True on AdminOnlyAccessPolicy messages. Get-QuarantineMessage returns the permissions of the person running it, not the recipient's. Use Get-QuarantinePolicy to see the end-user permissions.
A user can request but not release a message even though the policy allows release. The message was quarantined as malware or high confidence phishing; release is never allowed for recipients there.
A released message never reaches the inbox, or is quarantined again. Microsoft lists non-Microsoft filtering services, outbound connectors and inbox rules as common causes. Released messages are re-delivered, so they show the re-delivery time rather than the original time.
You can't edit a default policy. Default policies are read-only. Create a custom policy and assign it instead.
An admin assigned through PIM can't manage quarantine. PIM role assignments aren't currently supported in quarantine.
Checklist
- Each quarantining verdict reviewed and mapped to No, Limited or Full access.
- Custom policies created; notifications enabled where users should be informed.
- Policies assigned in anti-spam, anti-phishing, anti-malware and Safe Attachments policies.
- Global settings configured: sender, logo, frequency and up to three languages.
QuarantineRetentionPeriodset to match your review process.- Release request alerts routed to the people who handle them.
- Allow entries added during release reviewed in the Tenant Allow/Block List.