How to Test Strict Security Preset Quarantine Workflows in Microsoft 365
Question details
An administrator needs to test quarantine workflows for malware, phishing, spam, and Safe Links under the Strict security preset in Microsoft 365.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Testing different email threat security policies and verifying that malicious or unsolicited messages are successfully routed to quarantine.
- Observed behavior
- Standard test methods like GTUBE messages are being rejected outright at the edge network rather than triggering the internal quarantine workflows, preventing proper workflow validation.
Ensure you perform all security preset testing in a controlled, non-production Microsoft 365 tenant to avoid disrupting your organization's actual mail flow and live security policies.
Test Malware Detection Workflows Using the EICAR Test File
Use the industry-standard EICAR test file to safely trigger malware detection policies and verify that your quarantine workflows function correctly.
The EICAR file is a safe, standardized string of text recognized by anti-malware engines as a virus for testing purposes. It allows you to simulate a malware attack without introducing actual harmful software to your environment.
Open a plain text editor (like Notepad), paste the standard EICAR anti-virus test file string into the document, and save it with a .txt or .com file extension.
Compose a new email from an external email account, attach the EICAR test file, and send it to a designated test user within your non-production Microsoft 365 tenant.
Log in to the Microsoft 365 Defender portal, navigate to Email & collaboration > Review > Quarantine, and confirm that the email containing the EICAR file was intercepted and quarantined by the Strict preset malware policy.

Test Spam Handling by Modifying Mail Flow Rules
Create a targeted mail flow rule that forces specific test messages to be treated as high-confidence spam, allowing you to test spam quarantine workflows.
Need a Lightweight, Secure Office Suite? Try WPS Office
While you manage complex backend security configurations in Microsoft 365, you can equip your organization with WPS Office—a secure, lightweight, and highly compatible alternative for everyday document tasks. It provides a familiar user interface, seamless migration, and robust file compatibility without the heavy overhead.
- 1. Download the installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install the software: Run the downloaded file and follow the straightforward on-screen instructions to complete the setup.
- 3. Start working securely: Open WPS Office and immediately begin creating, editing, and saving your documents with full Microsoft format compatibility.

Frequently Asked Questions
Why are GTUBE messages rejected instead of quarantined in Microsoft 365?
Under strict network configurations, GTUBE (Generic Test for Unsolicited Bulk Email) messages are often blocked outright at the network edge by Microsoft's perimeter defenses before they can be evaluated by internal policies, making them unsuitable for testing post-delivery quarantine workflows.
Can I test all Strict security preset workflows with a single test email?
No. Because Microsoft 365 utilizes different engines and logic for malware, phishing, and spam, you must test each workflow separately. Methods that trigger malware policies (like EICAR) will not simultaneously validate spam or phishing quarantine behaviors.
Where do administrators view quarantined messages in Microsoft 365?
Administrators can view and manage all quarantined messages by navigating to the Microsoft 365 Defender portal, expanding the 'Email & collaboration' section, and selecting 'Review' followed by 'Quarantine'.




