How to Configure High-Confidence Phishing Quarantine in Microsoft Defender
Question details
Administrators need to understand why high-confidence phishing emails are quarantined and how to set up user notifications and release requests.

- Product
- Microsoft Defender
- Device & OS
- not provided
- Scenario
- Configuring email filtering and quarantine policies to handle legitimate messages that are incorrectly flagged as high-confidence phishing.
- Observed behavior
- High-confidence phishing messages are routed directly to quarantine instead of the Junk Email folder, preventing users from seeing them without administrator intervention.
Ensure you have the necessary administrator privileges in the Microsoft 365 Defender admin center to modify threat policies and anti-spam settings.
Enable User Quarantine Notifications and Release Requests
Configure your inbound anti-spam policy so users are notified of quarantined items and can request an administrator review.
By default, high-confidence phishing emails are heavily restricted to protect your organization. However, applying a notification policy allows users to see what was blocked and request access if a legitimate email was caught in the filter.
Log in to the Microsoft Defender admin center and navigate to 'Policies and rules' in the left-hand menu, then select 'Threat policies'.
Click on 'Anti-spam policies' and select your active inbound anti-spam policy to open its configuration panel.
Scroll through the policy settings to find the action designated for 'High confidence phishing'.
Change the quarantine policy to 'DefaultFullAccessWithNotificationPolicy'. This allows users to receive email notifications regarding quarantined items and request that administrators review and release them.

Adjust Filtering for Third-Party Security Tools
If your organization uses an external email security product, adjust Defender to prevent double-filtering and false quarantines.
Looking for a Secure and Lightweight Office Suite?
While managing complex email security policies in Microsoft 365, you might also be looking for a more streamlined, hassle-free office suite for your daily document tasks. WPS Office provides a free, highly compatible alternative to Microsoft Office with a familiar interface and excellent performance.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package.
- 2. Run the Setup: Open the downloaded file and follow the straightforward on-screen instructions to install the suite.
- 3. Start Creating: Launch WPS Office and instantly open your existing Microsoft Office documents without any formatting loss.

Frequently Asked Questions
Why don't high-confidence phishing emails go to the Junk folder?
Microsoft Defender applies stricter security measures to high-confidence phishing emails to protect organizations from severe threats. It sends them directly to quarantine to prevent users from accidentally clicking malicious links in their Junk folder.
Can standard end-users release high-confidence phishing emails themselves?
No, for high-confidence phishing detections, standard users cannot release the emails directly. They can only request a release, which an administrator must then review and manually approve.
How long does a released message stay on the allow list?
When an administrator releases a message and adds the sender to the allow list, that entry typically expires automatically after 30 days.
How can administrators get notified about quarantined messages?
Administrators can configure alert policies within the Microsoft Defender admin center to send specific quarantine notifications to a designated admin mailbox for regular review, rather than relying solely on the tenant administrator's email.




