How to Find Emails Quarantined by Microsoft ZAP
Question details
Administrators need to locate and manage emails that have been retroactively moved to quarantine by Microsoft Defender's Zero-hour Auto Purge (ZAP) feature.
- Product
- Microsoft Defender for Office 365
- Device & OS
- not provided
- Scenario
- Tracking down messages that were removed post-delivery due to malicious content detected by ZAP.
- Observed behavior
- Emails are successfully quarantined by ZAP, and administrators need to investigate or track these messages using Microsoft 365 security tools.
Ensure you have the necessary administrator permissions (such as Security Administrator or Global Admin) and an active Microsoft Defender for Office 365 Plan 2 license to access Threat Explorer.
Use Threat Explorer to Locate Quarantined Emails
Threat Explorer provides a graphical interface to search and filter for messages moved to quarantine by ZAP.
Log in to the Microsoft Defender portal (security.microsoft.com) using your administrator credentials.
In the left-hand navigation menu, select 'Email & collaboration' and click on 'Explorer' (Threat Explorer).
Set your desired date range, then use the filtering options to search by sender, subject, recipient, or action to isolate the emails moved to quarantine by ZAP.
Use Advanced Hunting with Kusto Queries
For more complex or bulk queries, use Advanced Hunting to locate ZAP quarantine actions programmatically.
Open a Support Service Request
If standard message tracing and Threat Explorer fail to provide answers, Microsoft support can assist with a back-end investigation.
Try WPS Office for a Streamlined Document Experience
While managing server-side security policies like ZAP requires Microsoft 365 admin tools, for everyday document creation and editing, WPS Office offers a lightweight, highly compatible, and free alternative to Microsoft Office. Enjoy seamless compatibility with Word, Excel, and PowerPoint files without the complex administrative overhead.
- 1. Download the Installer: Visit the official WPS Office website and click the Free Download button.
- 2. Install WPS Office: Run the downloaded installer file on your computer and follow the straightforward on-screen instructions.
- 3. Open and Edit: Launch WPS Office and instantly open your existing Microsoft Office files to start editing.

Frequently Asked Questions
What is Microsoft Zero-hour Auto Purge (ZAP)?
Zero-hour Auto Purge (ZAP) is a security feature in Microsoft Defender for Office 365 that retroactively detects and moves malicious phishing, spam, or malware messages to quarantine after they have already been delivered to a user's inbox.
Who can access Threat Explorer in Microsoft 365?
Threat Explorer is available to administrators with the appropriate security roles, such as Security Administrator or Global Administrator, and requires an active Microsoft Defender for Office 365 Plan 2 license.
Can I release a message quarantined by ZAP?
Yes, Microsoft 365 administrators can review messages in the quarantine portal and choose to release them to the recipient if they determine the message is safe or a false positive.
Why can't I see Threat Explorer in my Defender portal?
If Threat Explorer is missing, your organization may not have the required Microsoft Defender for Office 365 Plan 2 subscription, or your specific user account lacks the necessary administrative permissions to view the tool.




