Microsoft 365 Exchange Online quarantines messages that are identified as spam, phishing, or malware. Administrators can configure quarantine notifications so that end users receive periodic email summaries of their quarantined messages and can take action on them without contacting the help desk.

Note: The old "End-user spam notifications" setting in anti-spam policies has been replaced by quarantine notifications in quarantine policies. The interface previously known as the Security & Compliance Center (protection.office.com) has been retired. All configuration now takes place in the Microsoft Defender portal at https://security.microsoft.com.

How Quarantine Notifications Work

When quarantine notifications are enabled, end users receive periodic email digests listing messages that are held in their quarantine. For each message, users can:

  • Review message – View full details in the quarantine portal
  • Release – Deliver the message to their inbox (if the quarantine policy permits)
  • Request release – Ask an admin to release the message (for high-confidence phishing and malware, users can only request, not self-release)
  • Block Sender – Add the sender to their Blocked Senders list (if permitted by policy)

Notification frequency can be set to every 4 hours, daily, or weekly.

Default Quarantine Policies and Notification Status

Microsoft 365 includes several built-in quarantine policies. Notifications are not enabled by default in the most common ones:

Quarantine PolicyNotifications EnabledNotes
AdminOnlyAccessPolicyNoAdmin-only; users cannot see quarantined messages
DefaultFullAccessPolicyNoUsers can manage their quarantine but receive no email notifications
DefaultFullAccessWithNotificationPolicyYesUsed automatically by Standard and Strict preset security policies
NotificationEnabledPolicyYesAvailable in some tenants; check your tenant for availability

If your organization uses the Standard or Strict preset security policies, quarantine notifications are already enabled through DefaultFullAccessWithNotificationPolicy. No additional configuration is needed.

For custom anti-spam policies, you must explicitly assign a quarantine policy that has notifications enabled.

Enable Quarantine Notifications via Preset Security Policies (Recommended)

The simplest way to enable quarantine notifications for all users is to apply a preset security policy.

  1. Go to the Microsoft Defender portal: https://security.microsoft.com
  2. Navigate to Email & collaboration > Policies & rules > Threat policies > Preset security policies
  3. Enable the Standard protection or Strict protection policy and assign it to your users
  4. These policies automatically use DefaultFullAccessWithNotificationPolicy, which includes quarantine notifications

Enable Quarantine Notifications via a Custom Anti-Spam Policy

If you manage custom anti-spam policies, follow these steps to assign a quarantine policy with notifications enabled.

  1. Go to https://security.microsoft.com/antispam
  2. Select your anti-spam policy from the list
  3. In the details flyout, find the Actions section and select Edit
  4. For each verdict type where the action is Quarantine message (e.g., Spam, High confidence spam), click the Select quarantine policy dropdown
  5. Choose DefaultFullAccessWithNotificationPolicy or NotificationEnabledPolicy (if available in your tenant)
  6. Save the policy

Customize Quarantine Notification Settings

Administrators can customize the appearance and frequency of quarantine notifications globally.

  1. Go to https://security.microsoft.com/quarantinePolicies
  2. Select Global settings
  3. Configure the following options:
    • Notification frequency: Every 4 hours, Daily, or Weekly
    • Display name / From address: The sender name shown in notification emails
    • Logo: Upload a custom logo for the notification email
    • Language translations: Add notification text in up to 3 languages
  4. Save changes

Where End Users Manage Their Quarantine

End users can view and manage their quarantined messages at:

https://security.microsoft.com/quarantine

They can also access quarantine directly from the links in their quarantine notification emails.

Notes and Limitations

  • Messages quarantined as malware or high-confidence phishing can only be released by an admin; end users can request release but cannot self-release these messages regardless of quarantine policy settings
  • Quarantine notifications for shared mailboxes are delivered only to users with FullAccess permission assigned directly or via a cloud-only security group
  • Quarantine notifications for messages sent to distribution groups or mail-enabled security groups are sent to all group members

Further Reading

]]>