Skip to content

Commit cccfe35

Browse files
authored
Merge branch 'main' into patch-2
2 parents 724f14d + fb12fe7 commit cccfe35

File tree

3 files changed

+58
-176
lines changed

3 files changed

+58
-176
lines changed

CloudAppSecurityDocs/use-case-admin-quarantine.md

Lines changed: 8 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,9 @@
11
---
22
title: Protect files with admin quarantine
33
description: This tutorial describes the scenario for using admin quarantine to control data breaches.
4-
ms.date: 02/16/2023
4+
ms.date: 08/20/2025
55
ms.topic: tutorial
6+
ms.reviewer: drormikdash
67
---
78

89
# Tutorial: Protect files with admin quarantine
@@ -23,19 +24,13 @@ In this tutorial, you'll learn how to use Microsoft Defender for Cloud Apps to d
2324
>
2425
> - For a list of apps that support admin quarantine, see the list of [governance actions](governance-actions.md).
2526
> - Files labeled by Defender for Cloud Apps can't be quarantined.
26-
> - Defender for Cloud Apps admin quarantine actions are limited to 100 actions per day.
27+
> - Defender for Cloud Apps admin quarantine actions is limited to 100 actions per day.
2728
> - Sharepoint sites that are renamed either directly or as part of domain rename can't be used as a folder location for admin quarantine.
2829
2930

3031
1. When a file matches a policy, the **Admin quarantine** option is available for the file.
3132

32-
1. Do one of the following actions to quarantine the file:
33-
34-
- Manually apply the **Admin quarantine** action:
35-
36-
:::image type="content" alt-text="quarantine action." source="media/quarantine-action.png" lightbox="media/quarantine-action.png":::
37-
38-
- Set it as an automated quarantine action in the policy:
33+
1. Set an automated quarantine action in the policy.
3934

4035
:::image type="content" alt-text="quarantine automatically." source="media/quarantine-automated.png" lightbox="media/quarantine-automated.png":::
4136

@@ -49,7 +44,7 @@ In this tutorial, you'll learn how to use Microsoft Defender for Cloud Apps to d
4944

5045
1. The user can only access the tombstone file. In the file, they can read the custom guidelines provided by IT and the correlation ID to give IT to release the file.
5146

52-
1. When you receive the alert that a file has been quarantined, go to **Policies** -> **Policy Management**. Then select the **Information Protection** tab. In the row with your file policy, choose the three dots at the end of the line, and select **View all matches**. This brings you the report of matches, where you can see the matching and quarantined files:
47+
1. When you receive the alert that a file has been quarantined, go to **Policies** -> **Policy Management**. Then select the **Information Protection** tab. In the row with your file policy, choose the three dots at the end of the line, and select **View all matches**. This brings you the report of matches, where you can see the matching and quarantined files:
5348

5449
:::image type="content" alt-text="Quarantined files." source="media/quarantine-alerts.png" lightbox="media/quarantine-alerts.png":::
5550

@@ -58,7 +53,7 @@ In this tutorial, you'll learn how to use Microsoft Defender for Cloud Apps to d
5853
1. Inspect the file in the quarantined folder on SharePoint online.
5954
1. You can also look at the audit logs to deep dive into the file properties.
6055
1. If you find the file is against corporate policy, run the organization's Incident Response (IR) process.
61-
1. If you find that the file is harmless, you can restore the file from quarantine. At that point the original file is released, meaning it's copied back to the original location, the tombstone is deleted, and the user can access the file.
56+
1. If you find that the file is harmless, you can restore the file from quarantine. At that point the original file is released, and copied back to the original location. The tombstone is deleted, and the user can access the file.
6257

6358
:::image type="content" alt-text="quarantine restore." source="media/quarantine-restore.png":::
6459

@@ -76,7 +71,7 @@ In this tutorial, you'll learn how to use Microsoft Defender for Cloud Apps to d
7671
1. Set file policies that detect breaches. Examples of these types of policies include:
7772

7873
- A metadata only policy such as a sensitivity label in SharePoint Online
79-
- A native DLP policy such as a policy that searches for credit card numbers
74+
- A native data loss prevention (DLP) policy such as a policy that searches for credit card numbers
8075
- An ICAP third-party policy such as a policy that looks for Vontu
8176

8277
1. Set a quarantine location:
@@ -90,7 +85,7 @@ In this tutorial, you'll learn how to use Microsoft Defender for Cloud Apps to d
9085
:::image type="content" alt-text="quarantine settings." source="media/quarantine-settings.png" lightbox="media/quarantine-settings.png":::
9186

9287
> [!NOTE]
93-
> Defender for Cloud Apps will create a quarantine folder on the selected site.
88+
> Defender for Cloud Apps creates a quarantine folder on the selected site.
9489
9590
1. For Box, the quarantine folder location and user message can't be customized. The folder location is the drive of the admin who connected Box to Defender for Cloud Apps and the user message is: This file was quarantined to your administrator's drive because it might violate your company's security and compliance policies. Contact your IT administrator for help.
9691

0 commit comments

Comments
 (0)