Microsoft Defender for Office 365
Email and collaboration

Quarantine End User

In brief

The article now explains that users can provide an attachment password for Safe Attachments rescanning. Safe files are released; malicious or unscannable files remain quarantined. It also documents the one-attempt limit, portal-only release flow, and password safety guidance.

What Defender admins need to know

No administrator action is stated. Administrators should use this guidance when communicating the release process to users.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • m365-security
  • tier1 ms.custom:
  • msecd-doc-authoring-10161015
  • seo-marvel-apr2020
  • sfi-image-nochange description: Users can learn how to view and manage quarantined email messages in Microsoft 365 that were meant to be delivered to them. ms.service: defender-office-365 adobe-target: true ms.date: 07/03/17/2026 ai-usage: ai-assisted appliesto:
  • Built-in security features for all cloud mailboxes
  • Malware: Anti-malware policies in the built-in security features for all cloud mailboxes or in Safe Attachments policies in Defender for Office 365. The Policy Type value indicates which feature was used.
  • Phishing: The spam filter verdict was Phishing or anti-phishing protection quarantined the message (spoof settings or impersonation protection).
  • High confidence phishing
  • Password protected item: Safe Attachments quarantined the message because it contains an encrypted (password-protected) attachment that can't be scanned. For more information, see Release messages that contain encrypted (password-protected) attachments.
  • Blocked sender: One of the following values:
    • Don't show blocked senders (default)
    • Show all senders
Release messages that contain encrypted (password-protected) attachments

If a message is quarantined because it contains an encrypted (password-protected) attachment that Safe Attachments couldn't scan, the message has the Password protected item quarantine reason value. You're prompted to enter the password for the attachment when you release the message. Enter the password that the sender used to protect the file. If the message has multiple password-protected attachments, they must all use the same password, and you enter that password once to evaluate and possibly release the message.

Microsoft Defender for Office 365 uses the password to run a new scan of the attachment before the message is released. The password is used only to open and rescan the attachment. It isn't stored. The message stays in quarantine while the attachment is rescanned:

  • If the attachment is found to be safe, the message is released to your mailbox.
  • If the attachment is found to be malicious or still can't be scanned, the message stays in quarantine for an admin to review.

You can't release these messages directly from a quarantine notification email. If you receive a quarantine notification for one of these messages, select Review message to open the message in the Microsoft Defender portal. On the Quarantine page, select :::image type="icon" source="media/defender-portal-icon-check-mark.png" border="false"::: Release email, and then enter the attachment password when you're prompted.

Request the release of quarantined email

If your quarantine policy doesn't allow you to directly release a message, you can request that an admin release it.

Manage quarantined messages in Microsoft Teams

Zero-hour auto purge (ZAP) is a protection feature that automatically removes potentially malicious chat messages in Microsoft Teams and places them in quarantine. Users can now view and manage these quarantined Teams messages in the Microsoft Defender portal. Quarantine notifications aren't supported for quarantined Teams messages.

  • Preview message: You can view the details of the message you selected.

Messages are automatically deleted from quarantine after the date shown in the Expires column if you don't release or manually remove the messages.

Related content