Microsoft 365

Quarantine policies in Defender for Office 365: release, notify, review

Create quarantine policies that decide who can release quarantined email, turn on quarantine notifications, and handle user release requests as an admin.

10 min read
On this page

Quarantine policies in Microsoft Defender for Office 365 and Exchange Online Protection decide two things for each type of detection: what recipients can do with their own quarantined messages (nothing, request release, or release) and whether they receive quarantine notifications. To change the defaults, create a custom quarantine policy in the Defender portal under Email & collaboration > Policies & rules > Threat policies > Quarantine policies, assign it to the verdict in your anti-spam, anti-phishing, anti-malware or Safe Attachments policy, and set the notification frequency and branding in Global settings. Malware and high confidence phishing can never be released by users themselves, only requested.

Who this is for and what you will have

This guide is for Microsoft 365 administrators who want to reduce help desk tickets about quarantined mail without letting users release dangerous messages. It applies to all organizations with cloud mailboxes; impersonation detections and Safe Attachments need Defender for Office 365. At the end you will have:

  • A quarantine policy design that matches each verdict to the right level of user access.
  • Custom policies created in the portal or in PowerShell.
  • Those policies assigned to your threat policies, with quarantine notifications turned on where you want them.
  • A process for reviewing release requests as an admin.

How quarantine policies work

Permission groups

A quarantine policy contains individual permissions, grouped into three presets:

PermissionNo accessLimited accessFull access
View message headerYesYesYes
Allow senderNoYesYes
DeleteNoYesYes
PreviewNoYesYes
Release a message from quarantineNoNoYes
Request release of a messageNoYesNo

With No access and notifications off, users don't see the messages at all. With No access and notifications on, users see their messages and get notifications, but the only action is View message headers (in quarantine) or Review message (in the notification). That combination is useful when you want users to know something was held without letting them act on it.

Default quarantine policies

Microsoft provides default policies whose settings are read-only:

Default policyPermission groupNotifications
AdminOnlyAccessPolicyNo accessOff
DefaultFullAccessPolicyFull accessOff
DefaultFullAccessWithNotificationPolicyFull accessOn
NotificationEnabledPolicyFull accessOn

NotificationEnabledPolicy only exists in organizations that existed before quarantine policies were introduced in July-August 2021 and had end-user spam notifications turned on. You can't delete AdminOnlyAccessPolicy, DefaultFullAccessPolicy or DefaultFullAccessWithNotificationPolicy.

Which policy each verdict uses

These are the default and preset assignments from Microsoft's recommended settings:

VerdictDefault policyStandard presetStrict preset
SpamDefaultFullAccessPolicyDefaultFullAccessPolicyDefaultFullAccessWithNotificationPolicy
High confidence spamDefaultFullAccessPolicyDefaultFullAccessWithNotificationPolicyDefaultFullAccessWithNotificationPolicy
PhishingDefaultFullAccessPolicyDefaultFullAccessWithNotificationPolicyDefaultFullAccessWithNotificationPolicy
High confidence phishingAdminOnlyAccessPolicyAdminOnlyAccessPolicyAdminOnlyAccessPolicy
BulkDefaultFullAccessPolicyDefaultFullAccessPolicyDefaultFullAccessWithNotificationPolicy
SpoofDefaultFullAccessPolicyDefaultFullAccessPolicyDefaultFullAccessWithNotificationPolicy
Malware (anti-malware)AdminOnlyAccessPolicyAdminOnlyAccessPolicyAdminOnlyAccessPolicy
Safe AttachmentsAdminOnlyAccessPolicyAdminOnlyAccessPolicyAdminOnlyAccessPolicy

A quarantine policy only matters when the verdict's action is to quarantine. By default, for example, spoof detections go to Junk Email in the default and Standard settings, so the spoof quarantine policy has no effect until you change the action.

What users can never release

Regardless of the quarantine policy, recipients can't release:

  • Messages quarantined as malware by anti-malware policies.
  • Messages quarantined as malware or phishing by Safe Attachments policies.
  • Messages quarantined as high confidence phishing by anti-spam policies.

If the policy grants release permission for these, users can only request release. Messages quarantined by mail flow rules with the action Deliver the message to the hosted quarantine don't support quarantine policies at all; admins manage those messages.

Prerequisites

  • Membership in the Quarantine Administrator, Security Administrator or Organization Management role group in the Defender portal, or the Security Administrator role in Microsoft Entra ID. If Defender XDR Unified RBAC is active for email and collaboration, the permission is Authorization and settings/Security settings/Core Security settings (manage) or Security operations/Security Data/Email & collaboration quarantine (manage).
  • Roles assigned through Privileged Identity Management aren't currently supported in quarantine, so use a permanent assignment for the admins who manage it.
  • Exchange Online PowerShell for the scripted steps.
  • An inventory of your threat policies, so you know where each quarantine policy will be assigned.

Step 1: Create a custom quarantine policy

A common design is to keep spam on Full access, but move phishing to Limited access with notifications, so users can see and request release of a suspected phishing message while an admin makes the final decision.

In the Defender portal

  1. In the Microsoft Defender portal, go to Email & collaboration > Policies & rules > Threat policies > Quarantine policy in the Rules section, or open https://security.microsoft.com/quarantinePolicies.
  2. Select Add custom policy.
  3. On Policy name, enter a unique name such as Phish-LimitedWithNotify. You can't rename a policy later.
  4. On Recipient message access, select Limited access. Or select Set specific access (Advanced) and choose a release action (blank, Allow recipients to request a message to be released from quarantine or Allow recipients to release a message from quarantine) plus any of Delete, Preview, Block sender and Allow sender.
  5. On Quarantine notification, select Enable, then choose whether to include messages quarantined from blocked sender addresses. If you exclude them, recipients aren't notified about messages quarantined for blocked senders or bulk detections.
  6. Review and select Submit.

In PowerShell

New-QuarantinePolicy takes the permissions as a single decimal number built from these bits:

PermissionDecimal value
PermissionToViewHeader128
PermissionToDownload (not used)64
PermissionToAllowSender32
PermissionToBlockSender16
PermissionToRequestRelease8
PermissionToRelease4
PermissionToPreview2
PermissionToDelete1

Add the values of the permissions you want. Never set both PermissionToRequestRelease and PermissionToRelease. Limited access is 32 + 8 + 2 + 1 = 43:

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
New-QuarantinePolicy -Name "Phish-LimitedWithNotify" -EndUserQuarantinePermissionsValue 43 -EsnEnabled $true

A "notify only" policy uses 0 with notifications on, so users see the message and its headers but can't act on it:

New-QuarantinePolicy -Name "NotifyOnly-NoAccess" -EndUserQuarantinePermissionsValue 0 -EsnEnabled $true

EsnEnabled defaults to $false, so leave it out only when you want no notifications.

Step 2: Assign the policy to threat policies

Each verdict that quarantines has its own quarantine policy setting.

Anti-spam policies

In the portal, open Threat policies > Anti-spam, select an inbound policy, select Edit actions, and choose the policy in Select quarantine policy next to each verdict set to Quarantine message. In PowerShell:

Set-HostedContentFilterPolicy -Identity "Human Resources" -PhishSpamAction Quarantine -PhishQuarantineTag "Phish-LimitedWithNotify"
Get-HostedContentFilterPolicy | Format-List Name,SpamAction,SpamQuarantineTag,PhishSpamAction,PhishQuarantineTag,HighConfidencePhishQuarantineTag,BulkQuarantineTag

The anti-spam policy's Retain spam in quarantine for this many days setting (QuarantineRetentionPeriod) also controls retention for anti-phishing quarantine. It defaults to 15 days in the default and custom policies and can be set from 1 to 30 days; the Standard and Strict presets use 30 days.

Anti-phishing, anti-malware and Safe Attachments

  • Anti-phishing: on the Actions page, each verdict set to Quarantine the message has an Apply quarantine policy box. The PowerShell parameters are SpoofQuarantineTag, TargetedUserQuarantineTag, TargetedDomainQuarantineTag and MailboxIntelligenceQuarantineTag on Set-AntiPhishPolicy.
  • Anti-malware: the Quarantine policy box on Protection settings, or Set-MalwareFilterPolicy -QuarantineTag. Use a policy with notifications on if you want recipients told about malware detections; they still can't release them.
  • Safe Attachments: Set-SafeAttachmentPolicy -QuarantineTag for detections, and QuarantineTagForBlockingEncryptedAttachments for password-protected attachments that couldn't be scanned (DefaultFullAccessWithNotificationPolicy by default).

A changed assignment only applies to messages quarantined after the change. Messages already in quarantine keep the policy they were quarantined with.

Step 3: Configure quarantine notifications globally

Open Quarantine policies and select Global settings. The settings apply to every policy with notifications turned on:

  • Specify sender address: an existing internal user. The default sender is quarantine@messaging.microsoft.com.
  • Use my company logo: uses the logo from your Microsoft 365 organization theme. PNG and JPEG logos are the most compatible across Outlook versions.
  • Send end-user spam notification every (days): Within 4 hours, Daily or Weekly.
  • Language-specific Sender display name, Subject and Disclaimer (up to 200 characters), for up to three languages. Select the language first, because values entered before choosing a language are cleared.

The PowerShell equivalent targets the global policy:

Get-QuarantinePolicy -QuarantinePolicyType GlobalQuarantinePolicy |
    Set-QuarantinePolicy -EndUserSpamNotificationFrequency 1.00:00:00 -OrganizationBrandingEnabled $true `
      -MultiLanguageSetting ('Default') -ESNCustomSubject ('You have quarantined messages') `
      -MultiLanguageSenderName ('Contoso Mail Security') `
      -MultiLanguageCustomDisclaimer ('Questions? Contact the service desk.')

Quarantine notifications aren't localized for on-premises mailboxes.

Step 4: Review and release as an admin

Admins see all quarantined messages, including malware, high confidence phishing and mail flow rule detections, at Email & collaboration > Review > Quarantine (https://security.microsoft.com/quarantine). Filter by Release status (Needs review, Release requested, Denied, Released), Policy type or quarantine reason.

When a user requests release, the status changes to Release requested and the built-in alert policy User requested to release a quarantined message notifies admins. Audit logging must be on for that alert, which it is by default. To act on a request:

  • Select Release (or Release email in the details flyout) to approve. You can send a copy to other recipients and, as a Security Administrator, submit the message to Microsoft as a false positive with an optional Tenant Allow/Block List allow entry.
  • Select Deny (or More > Deny release). Denial applies to all recipients of the message.

You can select up to 100 messages for bulk actions. In PowerShell:

Get-QuarantineMessage -MessageID "<5c695d7e-6642-4681-a4b0-9e7a86613cb7@contoso.com>" |
    Release-QuarantineMessage -User julia@contoso.com

Use -ReleaseToAll instead of -User to release to every original recipient; recipients who already received a released copy are skipped. When you need to understand why a message never arrived after release, trace it as described in message trace with Get-MessageTraceV2.

Verify the configuration

  1. Run Get-QuarantinePolicy | Format-Table Name and confirm your custom policies exist.
  2. Run the Get-HostedContentFilterPolicy, Get-AntiPhishPolicy, Get-MalwareFilterPolicy and Get-SafeAttachmentPolicy commands with their *QuarantineTag properties and confirm each verdict uses the intended policy.
  3. Wait for a real detection, or review the Quarantine page for a recent message, and confirm the recipient sees the actions you expect.
  4. Confirm a test user receives a notification on the schedule you set.

Troubleshooting

Users don't receive notifications. The verdict uses a policy with notifications off, or the message was quarantined before you changed the assignment. Also check the frequency in Global settings: with Daily or Weekly, notifications arrive only on that schedule.

Admins see PermissionToRelease as True on AdminOnlyAccessPolicy messages. Get-QuarantineMessage returns the permissions of the person running it, not the recipient's. Use Get-QuarantinePolicy to see the end-user permissions.

A user can request but not release a message even though the policy allows release. The message was quarantined as malware or high confidence phishing; release is never allowed for recipients there.

A released message never reaches the inbox, or is quarantined again. Microsoft lists non-Microsoft filtering services, outbound connectors and inbox rules as common causes. Released messages are re-delivered, so they show the re-delivery time rather than the original time.

You can't edit a default policy. Default policies are read-only. Create a custom policy and assign it instead.

An admin assigned through PIM can't manage quarantine. PIM role assignments aren't currently supported in quarantine.

Checklist

  • Each quarantining verdict reviewed and mapped to No, Limited or Full access.
  • Custom policies created; notifications enabled where users should be informed.
  • Policies assigned in anti-spam, anti-phishing, anti-malware and Safe Attachments policies.
  • Global settings configured: sender, logo, frequency and up to three languages.
  • QuarantineRetentionPeriod set to match your review process.
  • Release request alerts routed to the people who handle them.
  • Allow entries added during release reviewed in the Tenant Allow/Block List.

References

Questions people ask

How do I let users request release of quarantined email instead of releasing it?

Create a quarantine policy with Limited access, or with Set specific access and the release action Allow recipients to request a message to be released from quarantine, then assign it to the verdict in your anti-spam or anti-phishing policy. Admins then approve or deny each request on the Quarantine page.

Why don't users get quarantine notifications?

Notifications are off in the default policies DefaultFullAccessPolicy and AdminOnlyAccessPolicy. Assign a quarantine policy with notifications turned on, such as DefaultFullAccessWithNotificationPolicy or a custom policy. The change only affects messages quarantined after you make it.

Can users release email quarantined as high confidence phishing or malware?

No. Messages quarantined as malware, as malware or phishing by Safe Attachments, or as high confidence phishing by anti-spam policies can't be released by recipients, whatever the quarantine policy says. If the policy allows release, users can only request it.

How long are messages kept in quarantine?

Anti-spam and anti-phishing quarantine uses the anti-spam policy's retention setting, 15 days by default and configurable from 1 to 30 days. Malware, Safe Attachments and mail flow rule quarantine is fixed at 30 days. Expired messages are permanently deleted.

Defender for Office 365Exchange Online ProtectionQuarantineExchange Online PowerShell
  1. Tenant Allow/Block List: allow spoofed senders and block domains safely

    Use the Tenant Allow/Block List in Microsoft Defender to allow legitimate spoofed senders with domain pairs and block domains without side effects.

    Microsoft 36511 min read
  2. Fix Microsoft 365 email going to Junk by reading SFV, CAT and compauth

    Work out why Exchange Online delivered a message to Junk Email from its anti-spam headers, then apply the fix that matches the component that filtered it.

    Microsoft 36513 min read
  3. Calendar permissions in Exchange Online: Add-MailboxFolderPermission guide

    Share calendars, change the organization-wide Default permission and add calendar delegates in Exchange Online with Add-, Set- and Remove-MailboxFolderPermission, including localized folder names.

    Microsoft 3659 min read