logo
search
Security Policy Errors

Fix Microsoft Defender User Reported Settings Save Error

Muhammad TalhaMuhammad Talha Oct 1, 2026 869 views

Question details

Users are unable to save changes to the Microsoft Defender user reported settings and receive a server error when updating the reported-message destination.

How to Fix Microsoft Defender User Reported Settings Save Error
Product
Microsoft Defender / Exchange Online
Device & OS
not provided
Scenario
Attempting to change the reported-message destination and saving configurations in Microsoft Defender user reported settings.
Observed behavior
A server error is thrown preventing the settings from being saved, which is often caused by the unexpected presence of duplicate DefaultReportSubmissionPolicy policies in the tenant.
Before you start

Ensure you have the necessary administrator permissions to connect to Exchange Online PowerShell and modify tenant policies before attempting to remove any duplicate configurations.

Solution 1Recommended

Remove the Duplicate DefaultReportSubmissionPolicy via PowerShell

Use Exchange Online PowerShell to identify and delete the conflicting duplicate policy that is causing the settings save error.

In some instances, Microsoft Defender tenants may erroneously generate two policies with the exact same name (DefaultReportSubmissionPolicy). This duplication creates a conflict that blocks the system from applying new reported-message destination settings.

To resolve this, you must locate the duplicate policy's unique identifier (GUID) and remove it manually.

1
Connect to Exchange Online PowerShell

Open PowerShell as an administrator and connect to Exchange Online using your tenant admin credentials.

2
Identify the duplicate policy

Run the command 'Get-ReportSubmissionPolicy' to list all submission policies. Look for duplicate entries named 'DefaultReportSubmissionPolicy' and copy the GUID of the unwanted policy.

3
Remove the conflicting policy

Execute the command 'Remove-ReportSubmissionPolicy -Identity <GUID>', replacing <GUID> with the unique identifier you copied in the previous step.

4
Apply your Microsoft Defender settings

Return to the Microsoft Defender portal and attempt to save your user reported settings again.

Remove the Duplicate DefaultReportSubmissionPolicy via PowerShell
Handling Permission Errors: If the Remove-ReportSubmissionPolicy command returns an error, verify that your account holds the correct administrative roles. If the duplicate policy still cannot be removed safely, you will need to contact Microsoft Support for further assistance.
Free Microsoft Office alternative

Looking for a Hassle-Free Office Suite? Try WPS Office

While you manage your organization's security policies and server configurations, you can empower your team with WPS Office—a highly compatible, lightweight, and free alternative to Microsoft Office for all everyday document tasks.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free version for your operating system.
  2. 2. Install WPS Office: Run the lightweight setup file and follow the quick on-screen instructions to complete the installation.
  3. 3. Open Your Files: Launch WPS Office and instantly open your existing Microsoft Word, Excel, or PowerPoint files without losing any formatting.
Fully compatible with Microsoft Office formats, including DOCX, XLSX, and PPTX.Easily draft, document, and share your IT security protocols and PowerShell scripts.Familiar user interface ensures a seamless migration for your entire team with zero learning curve.Lightweight design that runs smoothly on almost any device without consuming massive system resources.
microsoft office alternative - wps office

Frequently Asked Questions

Why do I get a server error when modifying reported-message destinations in Microsoft Defender?

This server error typically occurs because your tenant contains duplicate 'DefaultReportSubmissionPolicy' objects. The system cannot determine which policy to update, resulting in a save failure.

How do I find the GUID of my duplicate DefaultReportSubmissionPolicy?

You can find the GUID by connecting to Exchange Online PowerShell and running the 'Get-ReportSubmissionPolicy' cmdlet. This will output a list of all policies along with their unique Identity GUIDs.

What should I do if the PowerShell command returns an error while deleting the policy?

First, ensure you are connected to Exchange Online PowerShell with proper administrative permissions. If your roles are correct and the error persists, it is recommended to open a support case with Microsoft to have the duplicate policy removed safely.