Giving users full access does not let them release malware. That permission is simply not honoured.
It is the detail that resolves most quarantine arguments. Release is ignored for messages quarantined as malware by anti-malware or Safe Attachments policies, and for high confidence phishing. Quarantine policies decide everything else: who sees what, who can act, and who gets told.

- 3 groupsNo access, limited access, full access
- 3 defaultsBuilt-in policies you cannot remove or edit
- 4 hoursFastest notification frequency available
- Never releasedMalware and high confidence phishing, by users
Eight decisions hiding behind one setting nobody configured.
Three preset permission groups
No access, limited access and full access. The distinction that matters most is between the last two: full access includes allowing recipients to release a message themselves, while limited access instead lets them request release, which routes to an administrator for approval.
Release that is never honoured
Even with full access, allowing recipients to release is not honoured for messages quarantined as malware by anti-malware policies or Safe Attachments policies, or as high confidence phishing by anti-spam policies. Those categories are administrator-only regardless of what your policy says.
Request release as the middle ground
Limited access is described as letting users do anything to their quarantined messages except release them without admin approval. For most organisations that is the right default: users triage their own mail, and a human decision sits in front of anything actually leaving quarantine.
Three built-in policies you cannot change
AdminOnlyAccessPolicy with no access and notifications off, DefaultFullAccessPolicy with full access and notifications off, and DefaultFullAccessWithNotificationPolicy with full access and notifications on. None can be removed, and their permissions and notification settings are read only.
Notifications, which are off in the strictest default
Quarantine notifications are disabled in AdminOnlyAccessPolicy. That is a deliberate design and it produces a common complaint: messages are quarantined correctly and nobody is told. Where notification matters, that requires a different policy rather than a different setting.
Notification frequency and what it really means
The options are within four hours, daily or weekly. Microsoft notes that at four hours, a message quarantined just after the last notification generation reaches the recipient slightly more than four hours later. So four hours is the cadence, not the maximum delay.
Retention, set in the anti-spam policy
How long quarantined messages are held is controlled by the retain spam in quarantine for this many days setting in anti-spam policies, and that retention period applies to messages quarantined by anti-spam and anti-phishing protection. It is a separate setting from the quarantine policy itself.
What new policies inherit if you say nothing
New anti-malware policies created without specifying a quarantine policy use AdminOnlyAccessPolicy, as do Safe Attachments policies for malware detections. Blocking unscannable encrypted attachments without specifying one uses DefaultFullAccessWithNotificationPolicy instead.
A user cannot release malware or high confidence phishing, whatever permissions you grant.
Microsoft states this as a footnote to the permission table, and it settles most of the internal debate about how permissive quarantine should be.
- Allow recipients to release a message from quarantine is not honoured for messages quarantined as malware by anti-malware policies or by Safe Attachments policies, or as high confidence phishing by anti-spam policies. Those verdicts remain administrator-only by design.
- That changes the risk calculation on granting full access. The nightmare scenario people picture, a user releasing an actual malware sample into their mailbox, is not possible through the permission model. What full access actually permits is release of spam, bulk and lower confidence verdicts.
- High confidence phishing is already quarantined with AdminOnlyAccessPolicy by default, so in most tenants that verdict is doubly locked: the assigned policy grants no access, and the release permission would not be honoured even if it did.
- The practical consequence is that limited access is a defensible default for the verdicts where users can act, because it gives them triage and preview while routing any actual release through an administrator. Full access is then a deliberate choice for lower-risk verdicts rather than a blanket setting.
Four things that make quarantine work for both sides.
We configure per verdict rather than per tenant
Quarantine policy is assigned per protection feature and per verdict, which means malware, high confidence phishing, spam and bulk can each have a different answer. Applying one policy across all of them either over-restricts the harmless verdicts or over-permits the serious ones.
We default to request release rather than release
Limited access lets users do anything with their quarantined messages except release them without admin approval. For most organisations that is the right balance: users triage and preview, and a person makes the release decision. It also creates a queue somebody has to own, which we set up deliberately.
We check whether anybody is actually being told
Quarantine notifications are disabled in AdminOnlyAccessPolicy, and that is the policy applied by default to several verdicts. The result is correctly quarantined mail that nobody knows about. Whether that is right depends on the verdict, and it should be a decision rather than an inheritance.
We explain what the permission model cannot do
The concern that stalls these projects is a user releasing malware. That is not possible: release is not honoured for malware from anti-malware or Safe Attachments policies, or for high confidence phishing. Saying so with the documentation behind it usually unblocks the decision in one meeting.
Four phases across roughly three to four weeks.
- 01Week 1
Establish what is assigned where
Quarantine policy is assigned per protection feature and per verdict, so the first job is a matrix: which policy is currently in effect for spam, high confidence spam, phishing, high confidence phishing, bulk, malware, Safe Attachments detections and unscannable encrypted attachments.
- Current quarantine policy per feature and verdict
- Notification state per assignment
- Retention period from the anti-spam policy
- Preset security policy usage identified
- 02Week 2
Decide the target position per verdict
Not one answer for everything. Malware and high confidence phishing stay administrator-only because release would not be honoured anyway. Spam and bulk are candidates for limited or full access depending on how much administrator time release requests would consume.
- Target permission group agreed per verdict
- Release versus request release decision made
- Notification requirement agreed per verdict
- Custom policies designed where defaults do not fit
- 03Week 3
Build custom policies and assign them
The three default policies cannot be edited, so anything other than their exact combinations requires a custom policy. Assignment is per feature and per verdict, which is where the configuration work actually is.
- Custom quarantine policies created
- Assignment completed per feature and verdict
- Notification frequency set with the four hour behaviour understood
- Retention period confirmed as intended
- 04Week 4
Brief people and set the operating rhythm
Users told what they will see and what they can do with it, and administrators given a routine for handling release requests. A request queue nobody watches is worse than not offering the option, because it looks like a route and is not.
- End user guidance issued
- Release request handling routine agreed with an owner
- Response time expectation set
- Review point scheduled against false positive volume
Six situations where quarantine configuration is the problem.
A business losing legitimate mail silently
The classic symptom of AdminOnlyAccessPolicy with notifications off. Mail is quarantined correctly, nobody is told, and the problem surfaces when a customer asks why nobody responded to their enquiry. Turning on notification for the appropriate verdicts fixes it in an afternoon.
An IT team spending hours on release requests
The opposite failure. Every quarantined message becomes a ticket because users can neither preview nor act. Limited access gives them preview and delete and keeps release under approval, which removes most of the volume without changing the security position.
A regulated firm that must approve every release
Where policy requires a human decision on anything leaving quarantine, limited access with request release is the direct expression of that. The approval step is a control with a record, rather than a rule people are asked to follow.
A provider where a missed message has consequences
Referrals, results and appointment mail all arrive by email, and a silently quarantined message is a clinical risk rather than an inconvenience. Notification frequency at four hours for the appropriate verdicts, combined with preview, meaningfully shortens the time to notice.
An organisation using preset security policies
Preset security policies use DefaultFullAccessWithNotificationPolicy to enable quarantine notifications, rather than DefaultFullAccessPolicy where notifications are off. Knowing which of those is in play explains a lot of otherwise confusing behaviour when comparing tenants or user groups.
A business that lost mail to retention expiry
Retention is set by the retain spam in quarantine for this many days setting in the anti-spam policy, and it applies to anti-spam and anti-phishing quarantined mail. Where notification frequency is weekly and retention is short, mail can expire before anybody sees the notice about it.
How UAE organisations handle quarantined mail.
| Feature | Configured per verdict | One policy for everything | Defaults, notifications off |
|---|---|---|---|
Users can triage their own mail | For safe verdicts | All or nothing | No |
Release requires approval where it should | Yes | Depends | Not offered |
Malware release attempted | Not possible | Not possible | Not possible |
Users notified of quarantined mail | Where appropriate | Uniformly | No |
Administrator workload from requests | Predictable | High or zero | Zero |
False positives found quickly | Yes | Sometimes | When somebody phones |
Retention period chosen deliberately | Yes | Inherited | Inherited |
Notification frequency chosen | Yes | Default | Not applicable |
Preset policy interaction understood | Yes | No | No |
End user experience tested | Yes | No | No |
What each preset group actually allows.
| Permission | No access | Limited access | Full access | |
|---|---|---|---|---|
| View message header | Yes | Yes | Yes | |
| Allow sender | No | Yes | Yes | |
| Block sender | No | No | No | |
| Delete | No | Yes | Yes | |
| Preview | No | Yes | Yes | |
| Release a message from quarantine | No | No | Yes | |
| Request a message be released | No | Yes | No | |
| AdminOnlyAccessPolicy uses | This group | No | No | |
| DefaultFullAccessPolicy uses | No | No | This group | |
| Quarantine notifications enabled | No, in AdminOnlyAccessPolicy | Configurable | Depends on the policy |
Five steps, and the first is building a matrix nobody has.
- 1
Document the current assignment per verdict
Which quarantine policy applies to spam, high confidence spam, phishing, high confidence phishing, bulk, malware, Safe Attachments detections and unscannable encrypted attachments, plus whether notifications are on for each and what retention is configured.
- 2
Agree the target per verdict with the business
Malware and high confidence phishing stay administrator-only, since release would not be honoured regardless. Spam and bulk are the real decision, and it turns on how much administrator time you want release requests to consume against how much user autonomy you want.
- 3
Build custom policies where the defaults do not fit
The three default policies cannot be removed and their permissions and notification settings are read only, so any other combination requires a custom policy. That is common, because full access with notifications and limited access with notifications are both frequently what an organisation wants.
- 4
Assign, set frequency and confirm retention
Assignment per feature and verdict, notification frequency chosen with the four hour cadence behaviour understood, and retention confirmed in the anti-spam policy so it is long enough for the notification frequency you selected.
- 5
Brief users and give the request queue an owner
End user guidance covering what they will see and what they can do, and an administrator routine for release requests with a stated response time. A request option nobody monitors is worse than not offering it, because users believe they have a route.
What organisations ask about quarantine policies.
Fifteen questions about your own quarantine configuration.
Current state
- Which policy applies to spam?Per verdict, not per tenant.
- Which applies to high confidence phishing?AdminOnlyAccessPolicy by default.
- Which applies to malware?AdminOnlyAccessPolicy if unspecified.
- Which applies to Safe Attachments detections?Same default.
- What is our quarantine retention period?Set in the anti-spam policy.
Permissions
- Do users get release or request release?The key distinction.
- Who approves release requests?Name them.
- How quickly are requests handled?Set an expectation.
- Do users know preview exists?It reduces requests.
- Are we using preset security policies?They use a specific default.
Notifications
- Are notifications on at all?Off in AdminOnlyAccessPolicy.
- What frequency is configured?Four hours, daily or weekly.
- Do users understand the delay?Slightly more than four hours.
- Do notifications reach shared mailboxes?Check it.
- Has anyone tested the end user view?From a normal account.
Check which quarantine policy is assigned to spam, and which to high confidence phishing.
They are assigned separately, per verdict, and most organisations have never chosen either. Whatever you find is what your users experience every time something is blocked.
Related Services
Explore more solutions that work great with this service
Tenant Allow/Block List
Manual overrides that do more than you expect
Threat Explorer
Answering who received it and who clicked
Defender for Office 365
Plan 1 versus Plan 2, and the ten second way to tell which you have
Anti-Phishing Policies
Impersonation protection, spoof handling and thresholds
Email Security Audit
Authentication, policy, exceptions, routing, mailboxes
Safe Links
Time-of-click URL checks in mail, Teams and Office
DMARC Audit UAE
Stop exact-domain spoofing, and keep your mail delivering
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes