Said It Here

Why do emails get trapped in Microsoft and Google quarantines?

Built-in platform security holds messages before third-party security tools can evaluate them, causing administrative overhead and user friction. This creates constant bottlenecks where end users repeatedly request the release of legitimate emails trapped in the system.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Reviewing and releasing or denying messages manually in the default platform quarantine
  2. 2
    Configuring third-party settings to surface defender quarantine emails alongside default ones
  3. 3
    relying on native built-in email protection
  4. 4
    running a proof of concept with multiple vendors in detect-only mode

In their words

Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.

r/sysadmin1 person · September 2026

At the moment, we rely on Gmail’s built-in email protection, and managing messages through Google’s quarantine has been frustrating.source ↗

Adsary · r/sysadmin · 2 upvotes
r/msp1 person · September 2026

My main problem is the MS quarantine holds a lot of things before Ironscales gets a change to have an opinion.source ↗

Emails held by MS quarantine also happen to be the largest source of challenged incidents where the end user wants it released.source ↗

RaNdomMSPPro · r/msp · 1 upvotes

Where this came up

People with this problem also raised