How to Review Microsoft 365 Quarantine Safely

A message in Microsoft 365 quarantine may be an ordinary false positive, a malicious file, or a convincing payment scam. Review it carefully before you release it, because opening an attachment or following a link can expose a business account.

The safest process keeps suspicious content isolated, verifies requests through trusted channels, and gives administrators control over high-risk messages. This guide explains the Microsoft 365 quarantine workflow for employees, managers, and IT teams.

Key Takeaways

  • Use the Microsoft Defender portal to review quarantined email, not the message content itself.
  • Don't click links, open attachments, reply, or release a suspicious message before verification.
  • Check the sender, recipient, subject, detection reason, and message headers.
  • Use a known vendor phone number, saved bookmark, or separate contact method to verify an unexpected request.
  • Users may be able to release or delete messages, or request an administrator's review, depending on tenant policy.
  • Malware and Safe Attachments phishing detections may not allow self-release.
  • Report confirmed phishing through the Report Message option in Outlook or your organization's approved process.
  • Record important decisions, especially when a message involves invoices, payroll, credentials, or sensitive information.

Why Microsoft 365 quarantine needs a cautious review

What quarantine means

Microsoft 365 quarantine holds email that Microsoft Exchange Online or Defender identifies as spam, phishing, malware, bulk mail, or another policy violation. The message stays separate from the inbox while the system or an authorized person decides what should happen next.

Quarantine is a protective control, not proof that every message is malicious. Legitimate invoices, automated notifications, newsletters, and vendor messages can be held when their content or sending pattern looks unusual.

Visibility also depends on the tenant's quarantine policy. Some employees can preview and release messages. Others can only request release, while certain high-confidence detections remain available only to administrators.

Why trust is not proof

A familiar display name, company logo, or sender address doesn't prove that a message is safe. Attackers can imitate a vendor, compromise a real account, or use a look-alike domain.

Treat requests involving passwords, bank details, gift cards, wire transfers, payroll changes, or urgent sign-ins as high risk. Microsoft 365 anti-phishing policies, SPF, DKIM, and DMARC can reduce spoofing, but they won't eliminate every fraudulent message.

Businesses that need a broader review can use this small business Microsoft 365 and email security checklist to connect quarantine decisions with MFA, forwarding controls, and domain protection.

Open Microsoft 365 quarantine safely

Use the Microsoft Defender portal

Sign in directly to the Microsoft Defender portal using a saved bookmark or a manually typed address. Avoid signing in through a link inside a quarantine notification if the notification itself looks suspicious.

In the portal, open Email & collaboration , then Review , Quarantine , and Email . Menu names can vary by tenant, license, role, and Microsoft 365 updates. A notification may also take you to the relevant quarantine view.

If you don't see the message or available actions, that may be expected. User access is controlled by quarantine policies and permissions, not only by the message's contents.

Confirm context before taking action

Before previewing or requesting release, check:

  • The sender and recipient addresses
  • The subject and approximate delivery time
  • The detection category or quarantine reason
  • Whether the message was expected
  • Whether the sender normally uses that address
  • Whether the request matches an open business transaction

Don't forward the message to coworkers for casual review. Forwarding can expose malicious content or make it harder for IT to preserve the original evidence. Use your organization's ticketing process or ask an administrator to inspect it in the Defender portal.

Inspect the message before releasing it

Preview without interacting

The quarantine view can provide a message preview and header information. Read the text inside the security portal, but don't click links, open attachments, copy credentials into a form, or reply to the sender.

Pay attention to unusual urgency, payment changes, password-reset instructions, unexpected invoices, and requests to bypass normal approval. A message that appears professional can still be fraudulent, especially when the sender wants immediate action.

If you must examine an attachment, ask IT to analyze it with approved security tools. Employees shouldn't download quarantined files to a workstation for inspection.

Verify through a separate channel

Verification should use information that didn't come from the suspicious message. For example, call the vendor using a phone number from an existing contract, prior statement, or known account portal. Visit the vendor's website through a saved bookmark or type the established address manually.

Don't call a number printed in the unexpected email. Don't use its sign-in link to confirm whether the message is real. Ask a known contact or manager to confirm the transaction through a separate email address or phone call.

A legitimate business request can wait for independent verification. An attacker wants you to trust the message's own instructions.

Save the original message, screenshots, headers, attachment name, and relevant phone numbers if your IT provider requests them. Preserve the evidence before deleting anything.

Release, request, delete, or report

Know what each action does

Depending on policy, the quarantine interface may offer these actions:

  • Release message , which sends the email to the recipient's inbox.
  • Request release , which sends the request to an administrator for approval.
  • Delete , which removes the quarantined message.
  • Preview , which displays message content without placing it in the inbox.
  • Allow or block sender , when the user's policy permits those controls.

Releasing a message doesn't guarantee that it is safe. Only release it after confirming the sender, business context, and content. If Microsoft offers Report message as having no threats , select that option only when the message has been verified as legitimate.

Avoid adding broad allow rules to solve repeated false positives. A domain-wide exception can let future malicious messages bypass protection. If a vendor is repeatedly blocked, ask IT to review authentication, impersonation settings, and the narrowest possible policy exception.

Handle false positives and phishing

For a legitimate message, request release if self-release isn't available. The administrator can review it and decide whether the message belongs in the inbox.

For suspected phishing, use the Report Message option in Outlook if your organization has enabled it. Follow your company's reporting procedure as well. Reporting gives the IT team evidence to review and helps improve filtering decisions.

Messages identified as malware or phishing by Safe Attachments may not be eligible for self-release. In those cases, users can request review where the tenant permits it, but the administrator should make the final decision.

If someone clicked a link, opened an attachment, or entered credentials, report the event immediately. IT may need to revoke active sessions, reset the password, review MFA methods, inspect mailbox rules, and scan the device.

Administrator workflow and permissions

Review messages for one user

An administrator should open the Microsoft Defender portal and search quarantine by recipient, sender, subject, message ID, or date. The exact filters depend on the portal version and available licensing.

Review the message and its detection reason before releasing or deleting it. Check whether similar messages reached other users, especially executives, finance staff, payroll personnel, and shared mailboxes.

Administrators should also check related activity when a suspicious message was released. Look for unusual sign-ins, new inbox rules, forwarding settings, delegates, OAuth consent, or changes to payment instructions. A Microsoft 365 audit log review checklist can help organize that investigation.

Approve requests carefully

The permission Take action on quarantined messages for all users , under Email & collaboration quarantine (manage) , allows authorized administrators to manage messages across the tenant. Use the least privilege needed for the role.

Quarantine management moved away from Exchange Online permissions in February 2023. Current administration uses Microsoft Defender, Microsoft Defender XDR, and Unified RBAC permissions, depending on the tenant configuration.

Before approving a release, confirm who requested it, why the message is needed, and what verification was completed. If the request involves money, credentials, or sensitive records, require a second person or business owner to confirm it.

Retention and documentation

Plan before automatic deletion

Quarantined messages are automatically deleted when their retention period ends, and deleted quarantine items aren't recoverable through the normal quarantine workflow.

Retention details can differ by policy and documentation. Microsoft guidance lists 15 days in one default context and 30 days for Standard and Strict settings. Other Microsoft 365 guidance describes 30 days as a default. Don't assume one universal number. Check the setting in your tenant and record it in your security documentation.

High-risk investigations should begin promptly. If a message may relate to fraud, account compromise, or a legal matter, preserve the original email and relevant logs through your approved process before the retention period expires.

Record the decision

A short record should include the date, affected user, sender, recipient, subject, detection reason, action taken, approver, and verification method. Note whether the message was released, deleted, reported, or left in quarantine.

For a false positive, document why the message was legitimate and whether an exception was created. Review allowed senders and domains regularly. An exception that no longer has a business reason can become a bypass.

For a confirmed phishing attempt, record who was notified and whether any user clicked, replied, opened a file, or shared information. If multiple accounts or financial processes were involved, escalate the incident to the managed IT provider, leadership, bank, insurer, or legal counsel as appropriate.

FAQ

Can users release every quarantined message?

No. The tenant's quarantine policy controls available actions. Some messages can be released by the user, while others require an administrator request. Malware and certain Safe Attachments phishing detections may not permit self-release.

Should I open an attachment from quarantine?

No. Don't open a quarantined attachment on your computer. Ask IT to analyze it with approved tools. A file can contain malware even when the email looks like a familiar invoice or document request.

What should I do if a legitimate email is quarantined?

Verify that you expected the message and that the sender address is correct. Preview it without clicking links or opening attachments, then use Request release if that is the available action. An authorized administrator can release it after review.

What if I already clicked the link?

Tell IT or your managed service provider immediately. Don't wait to see whether anything happens. If you entered a password, report that detail clearly so the team can reset the account, revoke active sessions, review sign-ins, inspect mailbox rules, and check the device.

How often should a business review quarantine?

The right schedule depends on message volume and risk. Finance and executive mailboxes may need daily attention, while smaller teams may use a defined weekly review. The important point is ownership, documented escalation, and a review after staffing, vendor, or policy changes.

Conclusion

Safe Microsoft 365 quarantine review depends on restraint and verification. Keep suspicious messages isolated, inspect them without interacting with their content, and confirm important requests through trusted channels.

Users should report uncertainty instead of releasing risky mail. Administrators should apply least-privilege permissions, monitor related account activity, and document every important decision. A careful process turns quarantine from a holding area into a reliable part of the business's email security program.

ASK AN IT PRO