How to Stop Legitimate Emails from Going to Microsoft Defender Quarantine
Question details
The user needs a permanent solution to prevent legitimate daily automated emails sent by a school's web-based system from being quarantined by Microsoft Defender.

- Product
- Microsoft Defender for Office 365
- Device & OS
- not provided
- Scenario
- Receiving essential daily automated emails from a trusted web-based school management system.
- Observed behavior
- Messages are consistently misclassified as phishing and placed in the Microsoft Defender quarantine, requiring an impractical manual release for over 20 messages a day.
Ensure you have Microsoft 365 Administrator privileges, and thoroughly verify the sender's domain, authentication results (SPF, DKIM, DMARC), and message headers to confirm the emails are genuinely safe before creating any bypass rules.
Add the Sender to the Tenant Allow/Block List
Use the Microsoft Defender portal to explicitly allow the trusted sender or domain, bypassing the standard phishing filters.
Adding a sender to the Tenant Allow/Block List ensures that their messages are not prematurely quarantined by anti-spam or anti-phishing policies. You should only use the narrowest possible entry (specific email address rather than an entire domain) to maintain security.
Log in to the Microsoft 365 Defender portal at security.microsoft.com using your administrator credentials.
In the left-hand navigation pane, scroll down to 'Email & collaboration' and click on 'Policies & rules'.
Click on 'Threat policies', then under the 'Rules' section, select 'Tenant Allow/Block Lists'.
Click on the 'Domains & addresses' tab, select 'Add', enter the specific no-reply email address of the school system, choose 'Allow', and save your changes.

Submit the Message as a False Positive
Submit the quarantined email directly to Microsoft for analysis to improve the filtering algorithm for your tenant.
Submit an Administrator Support Ticket
Contact Microsoft Support directly if standard allow policies are ignored due to severe policy-level phishing verdicts.
Simplify Your Workflow with WPS Office
While managing complex Microsoft 365 security policies like Defender quarantines can be challenging and time-consuming, your daily document tasks shouldn't be. WPS Office offers a free, lightweight, and user-friendly alternative to Microsoft Office, ensuring seamless document management without the administrative overhead.
- 1. Download WPS Office: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install and Launch: Run the installer, follow the on-screen instructions, and launch the application.
- 3. Open Your Documents: Simply double-click your existing Microsoft Office files (.docx, .xlsx, .pptx) to open and edit them seamlessly in WPS Office.

Frequently Asked Questions
Why are legitimate automated emails marked as high-confidence phishing?
Automated emails often fail sender authentication checks (like SPF, DKIM, or DMARC) if the web-based system's IP address is not properly authorized in the sending domain's DNS records. Microsoft Defender will flag these authentication failures as spoofing or phishing.
Can standard users release quarantined phishing emails?
By default, emails classified as high-confidence phishing are quarantined and can only be reviewed and released by a Microsoft 365 Administrator, not by standard end-users.
How long do emails stay in the Microsoft Defender quarantine?
The default retention period for quarantined messages in Microsoft Defender is 30 days. After this period, the messages are permanently deleted and cannot be recovered.
Will adding a domain to the allow list stop all spam filtering for it?
Adding a domain to the Tenant Allow/Block List prevents messages from being blocked by spam, spoofing, and phishing filters. However, malware filters will still apply, and any email containing a malicious attachment will be blocked regardless of the allow list.




