logo
search
Security Policy Errors

How to Fix Microsoft Defender Blocking OneDrive Sharing Invitation Emails

Maira MehtabMaira Mehtab Sep 28, 2026 869 views

Question details

Users report that legitimate OneDrive sharing invitation emails are not being delivered to recipients because Microsoft Defender flags them as high-confidence phishing.

Product
Microsoft Defender / OneDrive
Device & OS
not provided
Scenario
Sending file or folder sharing invitations via OneDrive.
Observed behavior
OneDrive sharing invitation emails are classified by Microsoft Defender as high-confidence phishing. The messages do not reach the recipients and completely bypass the standard user quarantine.
Before you start

Ensure you have administrator access to the Microsoft 365 Defender portal, as you will need elevated privileges to review anti-phishing investigation results and modify allow-listing policies.

Solution 1Recommended

Review Defender Investigation Results and Adjust Allow-Listing

Use the Microsoft 365 Defender portal to safely allow-list legitimate OneDrive sharing notifications without compromising your organization's overall anti-phishing security.

When Microsoft Defender intercepts emails as high-confidence phishing, they are often routed away from standard user quarantine to protect the network. Instead of broadly disabling security policies, administrators should use targeted allow-listing.

1
Access Microsoft 365 Defender

Navigate to security.microsoft.com and log in with your administrator credentials to access the Microsoft 365 Defender portal.

2
Review the investigation results

Go to 'Email & collaboration' > 'Explorer' (or 'Threat Explorer'). Search for the blocked OneDrive sharing invitation emails to confirm they were flagged as high-confidence phishing.

3
Implement targeted allow-listing

Use the Defender portal's allow-listing procedures (such as Tenant Allow/Block Lists) to explicitly permit the legitimate OneDrive sending domains or IPs. Avoid broadly allowing suspicious messages.

4
Seek advanced support if necessary

If legitimate messages continue to be blocked after adjusting policies, post your issue in Microsoft Q&A using the 'Microsoft Defender' and 'OneDrive Management' tags, or contact Microsoft Support directly.

Security Warning: Do not disable your anti-phishing policies to bypass this error. Doing so exposes your organization to actual malicious phishing attacks. Always rely on targeted allow-listing.
Free Microsoft Office alternative

Experience Hassle-Free Document Sharing with WPS Office

Tired of dealing with complex security policies and blocked sharing invitations in Microsoft Office? Try WPS Office. It provides a lightweight, user-friendly environment with built-in cloud sharing that avoids complicated email routing issues while remaining fully compatible with Microsoft formats.

  1. 1. Open your document in WPS Office: Launch the WPS Office application and open the file you wish to share.
  2. 2. Click the Share button: Locate and click the 'Share' button in the top right corner of the application window.
  3. 3. Generate a secure link: Select 'Create Link' to generate a secure sharing link that you can directly copy and send to your recipients via any messaging platform.
Easily share documents via direct secure links, bypassing strict corporate email phishing filters.Fully compatible with Microsoft Office formats including DOCX, XLSX, and PPTX.Lightweight installation and a familiar interface for zero learning curve.Built-in robust cloud storage for seamless, real-time collaboration.
microsoft office alternative - wps office

Frequently Asked Questions

Why does Microsoft Defender flag legitimate OneDrive sharing emails as phishing?

Microsoft Defender uses strict machine-learning algorithms to detect threats. Occasionally, legitimate sharing links trigger high-confidence phishing alerts due to similarities with patterns used by attackers, especially if the internal routing or sender's domain lacks strict authentication alignments.

Why are the blocked OneDrive emails not appearing in my quarantine?

Emails classified as 'high-confidence phishing' are often subject to strict routing policies or zero-hour auto purge (ZAP). These mechanisms bypass standard, user-accessible quarantine to prevent users from accidentally releasing highly dangerous payloads.

Can I temporarily turn off the anti-phishing policy to let the OneDrive emails through?

It is strongly advised not to disable your anti-phishing policies. Doing so exposes your entire organization to real security threats. Instead, administrators should use targeted Tenant Allow/Block Lists to permit specific, verified OneDrive sharing domains.