Microsoft Defender for Office 365
Email and collaboration

Quarantine Admin Manage Messages Files

In brief

The documentation now lists Security Operator alongside Global Reader and Security Reader for read-only and preview/download access to quarantined messages. It also documents handling of encrypted Safe Attachments items and clarifies that Get-QuarantineMessage permission properties reflect the executing user.

What Defender admins need to know

Administrators can use the updated role and permission guidance when reviewing quarantine access and interpreting cmdlet results.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  - _Submit messages from quarantine to Microsoft_:  Membership in the **Security Administrator** role.
  - _Use **Block sender** to [add senders to your own Blocked Senders list](#block-email-senders-from-quarantine)_: Admins see **Block sender** only if they filter the quarantine results by **Recipient** \> **Only me** instead of the default value **All users**. Assigning any permission that gives admin access to quarantine (for example, **Security Reader** or **Global Reader**) gives access to **Block sender** in quarantine if the user filters the quarantine results by **Recipient** \> **Only me**.
- _Read-only access to quarantined messages for all users_: Membership in the **Global Reader**, **Security Reader**, or **Security Operator** roles.
- _Preview and download quarantined messages for all users_: Membership in the **Global Reader**, **Security Reader**, or **Security Operator** roles.
  • Admin action - File type block: Messages blocked as malware by the common attachments filter in anti-malware policies. For more information, see Anti-malware policies.
  • Phishing: The spam filter verdict was Phishing or anti-phishing protection quarantined the message (spoof settings or impersonation protection).
  • High confidence phishing
  • Password protected item: Safe Attachments quarantined the message because it contains an encrypted (password-protected) attachment that can't be scanned. For more information, see Encrypted (password-protected) attachments in Safe Attachments policies.
  • Recipient: Select one of the following values:
    • All users (the default value, even if it doesn't appear selected)
    • Only me: Show messages sent to the currently signed in recipient only. This value is required for admins to see the Allow sender and Block sender actions.
  • You can't choose to release messages only to recipients who didn't receive the released message.
  • Members of the Security Administrators role group can see and use the Submit the message to Microsoft to improve detection and Allow email with similar attributes options.
  • Users can report false positives to Microsoft from quarantine, depending on the value of the Reporting from quarantine setting in user reported settings.
  • For messages quarantined by Safe Attachments because they contain an encrypted (password-protected) attachment that couldn't be scanned, you release the message with full authority without providing the attachment password. Only end users are prompted for the password when they release these messages themselves. For more information, see Encrypted (password-protected) attachments in Safe Attachments policies.

Related content