how to release a quarantined email in microsoft defender
Releases a quarantined email in Microsoft Defender: finding the message and releasing it safely. Use when a legitimate email lands in quarantine. Not for releasing actual phishing.
TL;DR
Legitimate mail lands in quarantine when Defender's filters are aggressive. Find the message in the quarantine, verify it is safe, release it to the recipient, and optionally allowlist the sender so it stops happening.
The query
how to release a quarantined email in microsoft defenderUse this when
- user reports a missing legitimate email
- vendor invoices repeatedly quarantined
- release requests from the helpdesk queue
Not for
- releasing actual phishing or malware (do not do this)
- bulk-releasing quarantine without review
- messages quarantined by a different system
Steps
- In the Defender portal, open Quarantine and search for the message. Expected output: the message located
- Preview the message and check the threat verdict details. Expected output: you are confident it is legitimate
- Release the message to the intended recipient. Expected output: the user receives it
- Report it as a false positive to improve filtering. Expected output: feedback submitted
- If the sender is trusted, add an allowlist entry for the sender or domain. Expected output: repeat quarantines prevented
- Tell the user what to do next time mail goes missing. Expected output: user knows the process
Provenance
Resolved from the public thread: https://vectle.com/posts/pstC5A3CUqLqILMJVVgJFjsA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.