You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-office-365/quarantine-faq.yml
+31-35Lines changed: 31 additions & 35 deletions
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ metadata:
6
6
ms.author: chrisda
7
7
author: chrisda
8
8
manager: deniseb
9
-
ms.date: 11/3/2023
9
+
ms.date: 08/05/2024
10
10
audience: ITPro
11
11
ms.topic: faq
12
12
@@ -81,7 +81,7 @@ sections:
81
81
82
82
If the quarantine policy requires users to request the release of messages or requires admins to release messages, an admin must [approve the release request](quarantine-admin-manage-messages-files.md#approve-or-deny-release-requests-from-users-for-quarantined-email) or [release the message](quarantine-admin-manage-messages-files.md#release-quarantined-email) before the message is available to users.
83
83
84
-
Note that presets policies does not allow for the customization of Quarantine policies.
84
+
You can't customize quarantine policies in preset security policies.
85
85
86
86
87
87
- question: |
@@ -96,7 +96,7 @@ sections:
96
96
- question: |
97
97
How can I prevent users from accessing quarantined messages?
98
98
answer: |
99
-
The default quarantine policy named AdminOnlyAccessPolicy prevents any user interaction with their quarantined messages. By default, this quarantine policy is used for messages that were quarantined as malware or high confidence phishing. In custom policies or the default policy for [protection features that support quarantining messages](quarantine-policies.md#step-2-assign-a-quarantine-policy-to-supported-features), admins can specify the AdminOnlyAccessPolicy as the quarantine policy to use. please note that you can prevent end users from accessing security.microsoft.com/quarantine
99
+
The default quarantine policy named AdminOnlyAccessPolicy prevents any user interaction with their quarantined messages. By default, this quarantine policy is used for messages that were quarantined as malware or high confidence phishing. In custom policies or the default policy for [protection features that support quarantining messages](quarantine-policies.md#step-2-assign-a-quarantine-policy-to-supported-features), admins can specify the AdminOnlyAccessPolicy as the quarantine policy to use. You can prevent end users from accessing `security.microsoft.com/quarantine`.
100
100
101
101
- question: |
102
102
How do I find out why a message was quarantined?
@@ -114,7 +114,7 @@ sections:
114
114
115
115
When a message expires from quarantine, you can't recover it.
116
116
117
-
please note that messages from blocked senders are hidden by default from the Quarantine view. User needs to unselect blocked sender filter in Quarantine to see all messages coming from blocked senders
117
+
By default, messages from blocked senders are hiddenfrom view in quarantine. Users need to select **Filter** and then deselect **Don't show blocked senders** to see all messages coming from blocked senders.
118
118
119
119
- question: |
120
120
A message was released from quarantine, but the original recipient can't find it. How can I determine what happened to the message?
@@ -126,9 +126,9 @@ sections:
126
126
127
127
Verify that you aren't using third party filtering before you open a support ticket about these issues.
128
128
129
-
In the case there is no third party security vendor preventing the message from reaching the user inbox, then the Admin can use force release functionality to release message (if the first release did not work)
129
+
If a third party filter isn't preventing the message from reaching the user's Inbox, then admins can use force release functionality to release message (if the first release didn't work).
130
130
131
-
Admin should try to release to an alternate mailbox if the force flag release does not work after third party filtering vendor is turned off
131
+
Admin should try to release the message to an alternate mailbox if the forced release doesn't work after third party filtering vendor is turned off.
132
132
133
133
- Inbox rules ([created by users in Outlook](https://support.microsoft.com/office/c24f5dea-9465-4df4-ad17-a50704d66c59) or by admins using the **\*-InboxRule** cmdlets in Exchange Online PowerShell) can move or delete messages from the Inbox.
134
134
@@ -141,7 +141,7 @@ sections:
141
141
142
142
Verify that you aren't using third party filtering before you open a support ticket about this issue.
143
143
144
-
Admins can also use Audit log to see who released a message from Quarantine
144
+
Admins can also use the audit log to see who released a message from Quarantine.
145
145
146
146
- question: |
147
147
Can I release or report more than one quarantined message at a time?
@@ -150,7 +150,7 @@ sections:
150
150
151
151
Admins can use the [Get-QuarantineMessage](/powershell/module/exchange/get-quarantinemessage) and [Release-QuarantineMessage](/powershell/module/exchange/release-quarantinemessage) cmdlets in Exchange Online PowerShell or standalone EOP PowerShell to find and release quarantined messages in bulk, and to report false positives in bulk.
152
152
153
-
Admins can also perform bulk delete operation from thier end
153
+
Admins can also bulk delete messages.
154
154
155
155
- question: |
156
156
Are wildcards supported when searching for quarantined messages? Can I search for quarantined messages for a specific domain?
@@ -213,8 +213,8 @@ sections:
213
213
214
214
Also, the protection policies in [preset security policies](preset-security-policies.md) are always applied _before_ custom protection policies. A user who's defined in the Standard or Strict preset security policy will never get a customized protection policy where the quarantine policy is customized to turn on quarantine notifications. For more information, see [Policy settings in preset security policies](preset-security-policies.md#policy-settings-in-preset-security-policies)
215
215
216
-
please note that Quarantine notification are not enabled for Exchange transport rule messages and Data Loss prevention messages as those messages have the AdminOnly Quarantine Policy. Quarantine notification will also not be generated for messages with DefaultFullAccess Quarantine Policy
217
-
216
+
Quarantine notifications aren't enabled for messages quarantined by Exchange mail flow rules (transport rules) or data loss prevention (DLP). These messages have the AdminOnly quarantine policy. Quarantine notifications are also no generated for messages with DefaultFullAccess quarantine policy.
217
+
218
218
- question: |
219
219
How do I customize quarantine notifications to add a custom logo?
220
220
answer: |
@@ -225,7 +225,7 @@ sections:
225
225
answer: |
226
226
See the permissions entry [here](quarantine-admin-manage-messages-files.md#what-do-you-need-to-know-before-you-begin).
227
227
228
-
please note that Admins can release Quarantine messages to external recipient that are not present in thier organization.
228
+
Admins can release quarantined messages to external recipients that aren't in their organization.
229
229
230
230
> [!TIP]
231
231
> The ability to manage quarantined messages using [Exchange Online permissions](/exchange/permissions-exo/permissions-exo) ended in February 2023 per MC447339.
@@ -242,40 +242,36 @@ sections:
242
242
answer: |
243
243
If a user deletes the message from the Teams client, the message is gone, so Preview isn't available in quarantine for the deleted message.
244
244
245
-
- question: |
246
-
I can't see the block sender action button and the Approve release button. What's going on?
245
+
- question: |
246
+
I can't see the **Block sender** button or the **Approve release** button. What's going on?
247
247
answer: |
248
-
Block sender action is disabled by default for Quarantine messages. However, Admins can create a custom Quarantine policy to include block sender action for end users
248
+
The **Block sender** action is disabled by default for quarantined messages. However, admins can create a custom quarantine policy to include the **Block sender** action for end users.
249
249
250
-
The Approve release button has been retired and replaced by the release button
250
+
The **Approve release** button has been retired and replaced by the **Release** button.
251
251
252
-
- question: |
253
-
Filter and search is not working. What's going on?
252
+
- question: |
253
+
**Filter** and **Search** aren't working. What's going on?
254
254
answer: |
255
-
The search box only applies to loaded Quarantine messages.
256
-
257
-
To filter by internet message ID, You need to ensure that the pointed brackets <> are always inluded (even on PowerShell)
255
+
The **Search** box applies to loaded quarantine messages only.
258
256
257
+
To filter by Internet Message ID, you need to ensure that angle brackets `<>` are always inluded (even in PowerShell).
259
258
260
-
- question: |
261
-
Released Quarantine messages are still showing up in Quarantine. What's going on?
259
+
- question: |
260
+
Released quarantine messages are still showing up in Quarantine. What's going on?
262
261
answer: |
263
-
Released messages will still show up/remain in Quarantine unless it is explicitly deleted from Quarantine
262
+
Released messages remain visible in quarantine unless they're explicitly deleted from quarantine.
264
263
265
-
- question: |
266
-
Release request Alert are not getting generated. What's going on?
264
+
- question: |
265
+
Release request alerts aren't being generated. What's going on?
267
266
answer: |
268
-
Audit log needs to enabled in order for Release request alert to be generated
267
+
Audit logging needs to be enabled (it's on by default).
269
268
270
-
- question: |
271
-
Duplicate / Multiple Quarantine notification sent to the same user
269
+
- question: |
270
+
Duplicate or multiple quarantine notifications are sent to the same user.
272
271
answer: |
273
-
mutiple/duplicate Quarantine notification will be sent to a sender address with different alias if SendFromAliasEnabled is True
274
-
272
+
Mutiple or duplicate quarantine notifications are sent if the SendFromAliasEnabled paraMETER value is True.
275
273
276
-
- question: |
277
-
I cant see all the recipient of a Quarantine message. What's going on?
274
+
- question: |
275
+
I can't see all recipientS of a quarantined message. What's going on?
278
276
answer: |
279
-
For a Quarantine message with a large number of recipients, we do not show all the recipients in the UX or Cmdlet. However, the Admin can use the View message header or preview message functionality to see all the recipients
280
-
281
-
277
+
For quarantine messages with a large number of recipients, we don't show all of the recipients. However, admins can use **View message header** or **Preview message** to see all recipients.
0 commit comments