logo
search
Security Policy Errors

How to Stop Legitimate Emails from Going to Microsoft Defender Quarantine

Olivia MillerOlivia Miller Oct 9, 2026 868 views

Question details

The user needs a permanent solution to prevent legitimate daily automated emails sent by a school's web-based system from being quarantined by Microsoft Defender.

How to Prevent Legitimate Emails from Going to Microsoft Defender Quarantine
Product
Microsoft Defender for Office 365
Device & OS
not provided
Scenario
Receiving essential daily automated emails from a trusted web-based school management system.
Observed behavior
Messages are consistently misclassified as phishing and placed in the Microsoft Defender quarantine, requiring an impractical manual release for over 20 messages a day.
Before you start

Ensure you have Microsoft 365 Administrator privileges, and thoroughly verify the sender's domain, authentication results (SPF, DKIM, DMARC), and message headers to confirm the emails are genuinely safe before creating any bypass rules.

Solution 1Recommended

Add the Sender to the Tenant Allow/Block List

Use the Microsoft Defender portal to explicitly allow the trusted sender or domain, bypassing the standard phishing filters.

Adding a sender to the Tenant Allow/Block List ensures that their messages are not prematurely quarantined by anti-spam or anti-phishing policies. You should only use the narrowest possible entry (specific email address rather than an entire domain) to maintain security.

1
Access Microsoft 365 Defender

Log in to the Microsoft 365 Defender portal at security.microsoft.com using your administrator credentials.

2
Navigate to Policies and Rules

In the left-hand navigation pane, scroll down to 'Email & collaboration' and click on 'Policies & rules'.

3
Open Threat Policies

Click on 'Threat policies', then under the 'Rules' section, select 'Tenant Allow/Block Lists'.

4
Add Permitted Sender

Click on the 'Domains & addresses' tab, select 'Add', enter the specific no-reply email address of the school system, choose 'Allow', and save your changes.

Add the Sender to the Tenant Allow/Block List
Monitoring Required: Monitor the allow list carefully. If the sender's system is ever compromised, the allow rule will let malicious emails bypass your filters.
Free Microsoft Office alternative

Simplify Your Workflow with WPS Office

While managing complex Microsoft 365 security policies like Defender quarantines can be challenging and time-consuming, your daily document tasks shouldn't be. WPS Office offers a free, lightweight, and user-friendly alternative to Microsoft Office, ensuring seamless document management without the administrative overhead.

  1. 1. Download WPS Office: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install and Launch: Run the installer, follow the on-screen instructions, and launch the application.
  3. 3. Open Your Documents: Simply double-click your existing Microsoft Office files (.docx, .xlsx, .pptx) to open and edit them seamlessly in WPS Office.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats.Lightweight and fast, requiring minimal system resources and zero complex backend security setups.Familiar user interface ensuring a seamless migration and zero learning curve.All-in-one suite for PDF, Word, Excel, and Presentation tasks.
QA img-9

Frequently Asked Questions

Why are legitimate automated emails marked as high-confidence phishing?

Automated emails often fail sender authentication checks (like SPF, DKIM, or DMARC) if the web-based system's IP address is not properly authorized in the sending domain's DNS records. Microsoft Defender will flag these authentication failures as spoofing or phishing.

Can standard users release quarantined phishing emails?

By default, emails classified as high-confidence phishing are quarantined and can only be reviewed and released by a Microsoft 365 Administrator, not by standard end-users.

How long do emails stay in the Microsoft Defender quarantine?

The default retention period for quarantined messages in Microsoft Defender is 30 days. After this period, the messages are permanently deleted and cannot be recovered.

Will adding a domain to the allow list stop all spam filtering for it?

Adding a domain to the Tenant Allow/Block List prevents messages from being blocked by spam, spoofing, and phishing filters. However, malware filters will still apply, and any email containing a malicious attachment will be blocked regardless of the allow list.