Glossary
Quarantine
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
The holding area for emails detected as spam, phishing, or malware by Exchange Online Protection and Defender for Office 365.
Quarantine in Microsoft 365 is the holding area for emails detected as spam, phishing, malware, or otherwise unsafe by Exchange Online Protection (EOP) and Microsoft Defender for Office 365. End users receive a daily quarantine notification listing recent quarantined messages and can self-release low-risk items; high-confidence detections (phish, malware) require admin review. Admins manage quarantine in the Defender portal at security.microsoft.com → Email & collaboration → Review → Quarantine. Retention is 30 days by default (configurable up to 30); after that, messages are auto-deleted. Quarantine policies control end-user permissions per detection category.
Worked example
An employee is expecting an important attachment from a new external vendor, but the message never arrives in their inbox — it's held in quarantine because the sending domain has no email history with the tenant and tripped a spam heuristic. The daily quarantine digest email lists the message with a preview and a "release" option; because the quarantine policy for that detection category (bulk/spam) permits self-release, the employee releases it themselves without needing to raise a helpdesk ticket. A message that had instead been flagged as high-confidence phishing would show up the same way in the digest, but the release option would be greyed out, requiring an admin to review it first.
Common pitfalls
Assuming every quarantined message needs an admin to review it is a common unnecessary bottleneck — quarantine policies deliberately separate detection categories so users can self-release low-risk items (bulk mail, some spam) while genuinely dangerous categories (phish, malware) stay locked to admin review only. Employees ignoring the daily quarantine digest entirely, having learned to treat it as noise, is a real support-desk failure mode — legitimate business email regularly ends up there, and never checking the digest means those messages simply expire and delete themselves after the retention window. And admins leaving default quarantine policies unreviewed can under- or over-permit end users for a given organisation's risk tolerance — the defaults are a reasonable starting point, not a fixed rule that fits every tenant equally well.