logo
search
Security Policy Errors

How to Test Strict Security Preset Quarantine Workflows in Microsoft 365

Kushani NimanthikaKushani Nimanthika Oct 8, 2026 868 views

Question details

An administrator needs to test quarantine workflows for malware, phishing, spam, and Safe Links under the Strict security preset in Microsoft 365.

How to Test the Strict Security Preset in Microsoft 365
Product
Microsoft 365
Device & OS
not provided
Scenario
Testing different email threat security policies and verifying that malicious or unsolicited messages are successfully routed to quarantine.
Observed behavior
Standard test methods like GTUBE messages are being rejected outright at the edge network rather than triggering the internal quarantine workflows, preventing proper workflow validation.
Before you start

Ensure you perform all security preset testing in a controlled, non-production Microsoft 365 tenant to avoid disrupting your organization's actual mail flow and live security policies.

Solution 1Recommended

Test Malware Detection Workflows Using the EICAR Test File

Use the industry-standard EICAR test file to safely trigger malware detection policies and verify that your quarantine workflows function correctly.

The EICAR file is a safe, standardized string of text recognized by anti-malware engines as a virus for testing purposes. It allows you to simulate a malware attack without introducing actual harmful software to your environment.

1
Create the EICAR test file

Open a plain text editor (like Notepad), paste the standard EICAR anti-virus test file string into the document, and save it with a .txt or .com file extension.

2
Send a test email

Compose a new email from an external email account, attach the EICAR test file, and send it to a designated test user within your non-production Microsoft 365 tenant.

3
Verify quarantine placement

Log in to the Microsoft 365 Defender portal, navigate to Email & collaboration > Review > Quarantine, and confirm that the email containing the EICAR file was intercepted and quarantined by the Strict preset malware policy.

Test Malware Detection Workflows Using the EICAR Test File
Workflow Limitations: Because the EICAR file specifically triggers malware policies, you will need separate tests for phishing and spam workflows, as one method will not trigger every Strict preset policy simultaneously.
Free Microsoft Office alternative

Need a Lightweight, Secure Office Suite? Try WPS Office

While you manage complex backend security configurations in Microsoft 365, you can equip your organization with WPS Office—a secure, lightweight, and highly compatible alternative for everyday document tasks. It provides a familiar user interface, seamless migration, and robust file compatibility without the heavy overhead.

  1. 1. Download the installer: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Install the software: Run the downloaded file and follow the straightforward on-screen instructions to complete the setup.
  3. 3. Start working securely: Open WPS Office and immediately begin creating, editing, and saving your documents with full Microsoft format compatibility.
Free and lightweight office suite for streamlined team deploymentSeamless compatibility with Microsoft Word, Excel, and PowerPoint formatsFamiliar user interface ensuring a zero-learning-curve migrationSecure local document processing for enhanced organizational data privacy
microsoft office alternative - wps office

Frequently Asked Questions

Why are GTUBE messages rejected instead of quarantined in Microsoft 365?

Under strict network configurations, GTUBE (Generic Test for Unsolicited Bulk Email) messages are often blocked outright at the network edge by Microsoft's perimeter defenses before they can be evaluated by internal policies, making them unsuitable for testing post-delivery quarantine workflows.

Can I test all Strict security preset workflows with a single test email?

No. Because Microsoft 365 utilizes different engines and logic for malware, phishing, and spam, you must test each workflow separately. Methods that trigger malware policies (like EICAR) will not simultaneously validate spam or phishing quarantine behaviors.

Where do administrators view quarantined messages in Microsoft 365?

Administrators can view and manage all quarantined messages by navigating to the Microsoft 365 Defender portal, expanding the 'Email & collaboration' section, and selecting 'Review' followed by 'Quarantine'.