Quarantine Admin Manage Messages Files
In brief
The documentation now lists Security Operator alongside Global Reader and Security Reader for read-only and preview/download access to quarantined messages. It also documents handling of encrypted Safe Attachments items and clarifies that Get-QuarantineMessage permission properties reflect the executing user.
What Defender admins need to know
Administrators can use the updated role and permission guidance when reviewing quarantine access and interpreting cmdlet results.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- _Submit messages from quarantine to Microsoft_: Membership in the **Security Administrator** role.
- _Use **Block sender** to [add senders to your own Blocked Senders list](#block-email-senders-from-quarantine)_: Admins see **Block sender** only if they filter the quarantine results by **Recipient** \> **Only me** instead of the default value **All users**. Assigning any permission that gives admin access to quarantine (for example, **Security Reader** or **Global Reader**) gives access to **Block sender** in quarantine if the user filters the quarantine results by **Recipient** \> **Only me**.
- _Read-only access to quarantined messages for all users_: Membership in the **Global Reader**, **Security Reader**, or **Security Operator** roles.
- _Preview and download quarantined messages for all users_: Membership in the **Global Reader**, **Security Reader**, or **Security Operator** roles.
- Admin action - File type block: Messages blocked as malware by the common attachments filter in anti-malware policies. For more information, see Anti-malware policies.
- Phishing: The spam filter verdict was Phishing or anti-phishing protection quarantined the message (spoof settings or impersonation protection).
- High confidence phishing
- Password protected item: Safe Attachments quarantined the message because it contains an encrypted (password-protected) attachment that can't be scanned. For more information, see Encrypted (password-protected) attachments in Safe Attachments policies.
- Recipient: Select one of the following values:
- All users (the default value, even if it doesn't appear selected)
- Only me: Show messages sent to the currently signed in recipient only. This value is required for admins to see the Allow sender and Block sender actions.
- You can't choose to release messages only to recipients who didn't receive the released message.
- Members of the Security Administrators role group can see and use the Submit the message to Microsoft to improve detection and Allow email with similar attributes options.
- Users can report false positives to Microsoft from quarantine, depending on the value of the Reporting from quarantine setting in user reported settings.
- For messages quarantined by Safe Attachments because they contain an encrypted (password-protected) attachment that couldn't be scanned, you release the message with full authority without providing the attachment password. Only end users are prompted for the password when they release these messages themselves. For more information, see Encrypted (password-protected) attachments in Safe Attachments policies.
- Preview-QuarantineMessage: This cmdlet is for messages only, not quarantined files.
- Release-QuarantineMessage
Related content
@@ -15,7 +15,7 @@ ms.custom: - sfi-image-nochange description: Admins can learn how to view and manage quarantined messages for all users in Microsoft 365 organizations with cloud mailboxes. Admins in organizations with Microsoft Defender for Office 365 can also manage quarantined files in SharePoint, OneDrive, and Microsoft Teams. ms.service: defender-office-365-ms.date: 07/03/2026+ms.date: 08/31/2026 ai-usage: ai-assisted appliesto: - ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Built-in security features for all cloud mailboxes</a>@@ -66,7 +66,8 @@ Before you begin, review the following portal access, permissions, and retention - _Take action on quarantined messages for all users_: Membership in the **Quarantine Administrator**, **Security Administrator**, or **Organization Management** role groups. - _Submit messages from quarantine to Microsoft_: Membership in the **Security Administrator** role groups. - _Use **Block sender** to [add senders to your own Blocked Senders list](#block-email-senders-from-quarantine)_: Admins see **Block sender** only if they filter the quarantine results by **Recipient** \> **Only me** instead of the default value **All users**. Assigning any permission that gives admin access to quarantine (for example, **Security Reader** or **Global Reader**) gives access to **Block sender** in quarantine if the user filters the quarantine results by **Recipient** \> **Only me**.- - _Read-only access to quarantined messages for all users_: Membership in the **Security Reader** or **Global Reader** role groups.+ - _Read-only access to quarantined messages for all users_: Membership in the **Global Reader**, **Security Reader**, or **Security Operator** role groups.+ - _Preview and download quarantined messages for all users_: Membership in the **Global Reader**, **Security Reader**, or **Security Operator** role groups. - [Microsoft Entra permissions](/entra/identity/role-based-access-control/manage-roles-portal): Membership in these roles gives users the required permissions _and_ permissions for other features in Microsoft 365: - _Take action on quarantined messages for all users_: Membership in the **Security Administrator** or **Global Administrator**<sup>\*</sup> roles. @@ -75,7 +76,8 @@ Before you begin, review the following portal access, permissions, and retention - _Submit messages from quarantine to Microsoft_: Membership in the **Security Administrator** role. - _Use **Block sender** to [add senders to your own Blocked Senders list](#block-email-senders-from-quarantine)_: Admins see **Block sender** only if they filter the quarantine results by **Recipient** \> **Only me** instead of the default value **All users**. Assigning any permission that gives admin access to quarantine (for example, **Security Reader** or **Global Reader**) gives access to **Block sender** in quarantine if the user filters the quarantine results by **Recipient** \> **Only me**.- - _Read-only access to quarantined messages for all users_: Membership in the **Global Reader** or **Security Reader** roles.+ - _Read-only access to quarantined messages for all users_: Membership in the **Global Reader**, **Security Reader**, or **Security Operator** roles.+ - _Preview and download quarantined messages for all users_: Membership in the **Global Reader**, **Security Reader**, or **Security Operator** roles. > [!NOTE] > Currently, roles assigned through Azure Privileged Identity Management aren't supported in quarantine. For more information about PIM, see [Privileged Identity Management (PIM) and why to use it with Microsoft Defender for Office 365](/defender-office-365/pim-in-mdo-configure).@@ -162,6 +164,7 @@ To filter the entries, select :::image type="icon" source="media/defender-portal - **Admin action - File type block**: Messages blocked as malware by the common attachments filter in anti-malware policies. For more information, see [Anti-malware policies](anti-malware-protection-about.md#anti-malware-policies). - **Phishing**: The spam filter verdict was **Phishing** or anti-phishing protection quarantined the message ([spoof settings](anti-phishing-policies-about.md#spoof-settings) or [impersonation protection](anti-phishing-policies-about.md#impersonation-settings-in-anti-phishing-policies-in-microsoft-defender-for-office-365)). - **High confidence phishing**+ - **Password protected item**: Safe Attachments quarantined the message because it contains an encrypted (password-protected) attachment that can't be scanned. For more information, see [Encrypted (password-protected) attachments in Safe Attachments policies](safe-attachments-about.md#encrypted-password-protected-attachments-in-safe-attachments-policies). - **Recipient**: Select one of the following values: - **All users** (the default value, even if it doesn't appear selected) - **Only me**: Show messages sent to the currently signed in recipient only. This value is required for admins to see the [Allow sender](#allow-email-senders-from-quarantine) and [Block sender](#block-email-senders-from-quarantine) actions.@@ -294,6 +297,7 @@ Messages are automatically deleted from quarantine after the date shown in the * - You can't choose to release messages only to recipients who didn't receive the released message. - Members of the **Security Administrators** role group can see and use the **Submit the message to Microsoft to improve detection** and **Allow email with similar attributes** options. - Users can report false positives to Microsoft from quarantine, depending on the value of the **Reporting from quarantine** setting in [user reported settings](submissions-user-reported-messages-custom-mailbox.md).+- For messages quarantined by Safe Attachments because they contain an encrypted (password-protected) attachment that couldn't be scanned, you release the message with full authority without providing the attachment password. Only end users are prompted for the password when they release these messages themselves. For more information, see [Encrypted (password-protected) attachments in Safe Attachments policies](safe-attachments-about.md#encrypted-password-protected-attachments-in-safe-attachments-policies). > [!TIP] >@@ -927,6 +931,9 @@ As an alternative to the Microsoft Defender portal, you can use the following [E - [Preview-QuarantineMessage](/powershell/module/exchangepowershell/preview-quarantinemessage): This cmdlet is for messages only, not quarantined files. - [Release-QuarantineMessage](/powershell/module/exchangepowershell/release-quarantinemessage) +> [!IMPORTANT]+> The _PermissionTo\*_ properties returned by **Get-QuarantineMessage** reflect the permissions of the user who runs the cmdlet. For example, admins who have permission to release quarantined messages might see the value `True` for the _PermissionToRelease_, _PermissionToAllowSender_, and _PermissionToDownload_ properties, even when the quarantine policy assigned to the message is `AdminOnlyAccessPolicy`. These values don't represent the actions available to message recipients. To view the end-user permissions configured in a quarantine policy, use **Get-QuarantinePolicy** as described in [View quarantine policies in PowerShell](quarantine-policies.md#view-quarantine-policies-in-powershell).+ <a name="for-more-information"></a> ## Related content 