Open the Junk Email folder on any mailbox at your firm and read it for a minute. Most of it is obvious. Somewhere in there will be one that isn't: a real company name in the subject line, a short note about changed bank details and a deadline. Microsoft 365 spam quarantine is the feature that keeps that message out of the mailbox entirely, and on almost every tenant it is switched off.
Microsoft put that message in Junk on purpose. The filter caught it. Junk is where the filter delivers what it catches, and Junk is a folder inside the mailbox, three rows down from a real client email, in a folder your bookkeeper opens twice a week looking for an attachment that got misfiled.
SDO CPA does tax and accounting work. I'm a partner. Our mail runs on Microsoft 365, same as most firms our size.
We were getting fifteen to twenty a day across a few accounts. It's close to nothing now. Quarantine is part of that and not all of it, because I changed a few things around the same time. The setup below took about half an hour.
Here's the part that surprises people. Microsoft is already filtering your spam. That's on. It's been on since the day you bought the licenses. What isn't on is where the filtered mail goes. By default it mostly goes to Junk, which your team can see and click. Quarantine holds it outside the mailbox, where getting it back is a deliberate act instead of a click while somebody is scanning fast. The switch that moves spam and phishing from one to the other ships turned off, and it stays off until an admin turns it on.
Most firms our size don't have an admin. They have an owner who is also the admin, who has never opened the page where that switch lives.
How do you turn on spam quarantine in Microsoft 365?
Microsoft 365 spam quarantine is almost certainly off in your tenant right now. Go to the Microsoft Defender portal at security.microsoft.com/presetSecurityPolicies, turn on the Standard protection preset security policy, and apply it to all recipients. That one switch changes high confidence spam and phishing from "move to Junk Email folder" to "quarantine," and it assigns the quarantine policy that emails users a daily summary of what got held. High confidence phishing is already quarantined by default. Set the notification frequency to daily, tell your team what that email looks like before it starts arriving, and watch the queue at security.microsoft.com/quarantine for two weeks. Budget thirty minutes, then five minutes a week.
Key Takeaways
Microsoft's default sends phishing to Junk - in the default anti-spam policy, four of the five spam verdicts (spam, high confidence spam, phishing, and bulk) are set to "move message to Junk Email folder." High confidence phishing is the one bucket already quarantined out of the box.
Junk sits inside the mailbox and quarantine sits outside it - anything in Junk is one click from being opened, forwarded, or marked "not junk" by a staff member who's moving fast.
The Standard preset is one switch, and it's off - turning it on quarantines high confidence spam and phishing, and drops the bulk mail threshold from 7 to 6.
Quarantine with no notification is what makes firms give up - that's my read on it, anyway. Microsoft ships three quarantine policies that look almost identical on screen, and only one of them tells your team anything. The default anti-spam policy uses one of the silent ones.
Held mail expires and is gone - 15 days under the default anti-spam policy, 30 days under the Standard and Strict presets. After that Microsoft deletes it permanently and nobody can get it back.
This is one control, not a security program - tax and accounting firms are financial institutions under the GLBA Safeguards Rule, and IRS Publication 5708 says the law requires a written plan. Quarantine is a line item in that plan. None of this is legal advice.
Settings, defaults and portal paths verified against Microsoft Learn on 4 September 2026. Microsoft moves these pages. If a link 404s, search the setting name from inside the Defender portal.
What Microsoft actually does with your spam right now
Every Microsoft 365 tenant has a default anti-spam policy. You didn't create it and you can't delete it. It applies to everyone who doesn't match a more specific policy, and it has been running since your first mailbox.
That policy sorts suspicious mail into five buckets and does something with each one. Here's what it does before anyone touches it:
Spam Move to Junk Email folder
High confidence spam Move to Junk Email folder
Phishing Move to Junk Email folder
High confidence phishing Quarantine
Bulk mail (BCL 7 or above) Move to Junk Email folderRead that list again with a staff member in mind. Four of five verdicts, including the one literally labeled phishing, get delivered into the mailbox. The message about changed bank details is sitting in a folder somebody scans twice a week at speed.
Four things are already on, and they're worth knowing about before you change anything:
Zero-hour auto purge pulls malware out of mailboxes after delivery when Microsoft's verdict changes.
Spoof intelligence catches senders forging your domain.
DMARC enforcement honors what a sending domain publishes when a message is detected as spoof. If they publish
p=quarantine, Microsoft quarantines it. If they publishp=reject, Microsoft rejects it outright.Malware attachments go to quarantine under an admin-only policy, so users never see them at all.
So the machine is running. It just delivers most of its verdicts to a folder that's still in the building.
Why the Junk folder is the wrong place for a firm
Three things go wrong with Junk, and they go wrong harder at an accounting firm than at a landscaping company.
Staff dig through it. They have to. Client documents end up there. Portal notifications end up there. So people scan Junk on purpose, at speed, looking for a false positive, which is the exact mental state where a good phishing message wins.
Safe senders are a private decision. Every mailbox keeps its own Safe Senders list, and the person who owns the mailbox maintains it in Outlook without telling anybody. A sender on that list gets delivered to the inbox. You can read those lists as an admin, but only through PowerShell, and nothing surfaces a change to you when it happens.
Shared mailboxes make it worse. Your info@ or billing@ address gets the highest volume of anything you own, and it's the mailbox nobody personally owns, so nobody personally maintains it.
And there's a fourth reason, specific to this profession. Under the Gramm-Leach-Bliley Act and the FTC's Safeguards Rule, tax and accounting practices count as financial institutions no matter how small they are. IRS Publication 5708 (Rev. 8-2024) puts it plainly: "Not only is a WISP essential for your business and a good business practice, the law requires you to have one."
I'm not a lawyer and this isn't legal advice, and turning on quarantine doesn't make you compliant with anything. But if you're going to write down the controls your firm actually runs, "spam and phishing are held outside the mailbox and reviewed daily" is a better line to write than "we tell everyone to be careful."
The Microsoft 365 spam quarantine setup, step by step
Thirty minutes. You need Security Administrator, or Organization Management in Exchange. Global Administrator also works, and if you set up Microsoft 365 originally that's probably what you're signed in as. Microsoft recommends against using it for routine work, so if you have a second admin account with a narrower role, use that one.
Before you touch anything
Check what you're licensed for. Go to https://admin.microsoft.com/Adminportal/Home#/subscriptions and look at your plan name. The anti-spam and quarantine features in this guide come with every Microsoft 365 subscription that has mailboxes, including Business Basic and Business Standard. Business Premium and E3 add Defender for Office 365 Plan 1, which brings Safe Links, Safe Attachments and impersonation protection. If you're on Business Premium you're already paying for the Defender features, so you may as well turn them on in the same sitting.
Fix your email authentication first. Microsoft says this explicitly, and it's the step people skip. If your own domain's SPF, DKIM and DMARC records are missing or wrong, tightening the filter will start catching your own legitimate mail, and you'll blame the filter. Sort authentication out before you change policy.
Decide who watches the queue. One named person, checking daily for the first two weeks. If that person is you, put it in your calendar now.
Step 1: Turn on the Standard preset
Go to https://security.microsoft.com/presetSecurityPolicies. If that link redirects, the page lives under Email & collaboration > Policies & rules > Threat policies > Preset security policies, in the Templated policies section.
You'll see three sections: Standard protection, Strict protection, and Built-in protection. Standard and Strict will almost certainly show as off. Built-in protection is on, and it covers only Safe Links and Safe Attachments for firms with a Defender license. It doesn't touch spam actions at all, which is why your spam is still going to Junk.
Slide Standard protection to On, then select Manage protection settings. The wizard walks you through:
Apply Exchange Online Protection. Choose All recipients. This page governs the anti-spam and anti-phishing settings, so it's the one that matters most. Scoping it to a test group and forgetting about it is how half a firm ends up unprotected.
Apply Defender for Office 365 protection. This page only appears if you have Business Premium, E3, E5 or a Defender add-on. Choose All recipients here too.
Impersonation protection. Defender licenses only. Add your firm's own domain, and add the names and email addresses of your partners and anyone who can approve a payment. This is the setting aimed at a message that looks like it's from you, addressed to your bookkeeper.
Review and confirm. Turning it on for the first time is what creates the underlying policies. There's no other supported way to make them.
That's the switch. Here's exactly what it changed:
Before (default) After (Standard)
Spam Move to Junk Move to Junk
High confidence spam Move to Junk Quarantine
Phishing Move to Junk Quarantine
High confidence phishing Quarantine Quarantine
Bulk mail Move to Junk (threshold 7) Move to Junk (threshold 6)
First contact safety tip Off OnTwo things worth noticing. Ordinary spam still goes to Junk under Standard, on purpose: it's the noisiest bucket and the one most likely to hold a newsletter somebody wanted.
And the first contact safety tip turns on. That puts a banner on the first message from any new sender, reading "You don't often get email from" followed by the actual sending address. Your staff will notice that one immediately, and it does more day-to-day work than most of the settings underneath it.
Step 2: Confirm the notification is actually on
This is the step that decides whether the whole thing survives.
Microsoft has several quarantine policies and they look almost identical. The difference is whether the user gets told:
AdminOnlyAccessPolicy User sees nothing, admin only
DefaultFullAccessPolicy User can view and release, NO notification
DefaultFullAccessWithNotificationPolicy User can view and release, notification ONThe default anti-spam policy assigns DefaultFullAccessPolicy to everything, with notifications off. Change the actions by hand instead of using the preset and you build a black hole: mail disappearing with nobody told. My read is that this is the version most firms try, and it's why quarantine gets switched off again a month later.
The Standard preset assigns DefaultFullAccessWithNotificationPolicy to high confidence spam and phishing, which is the reason using the preset beats hand-configuring. Check it at https://security.microsoft.com/quarantinePolicies.
Two exceptions to tell your team about. Nobody can release a high confidence phishing message themselves, no matter what the policy says; they can only request the release, which comes to you. Malware is stricter again. It's held under AdminOnlyAccessPolicy, so users never see those messages and have no request option at all.
Step 3: Set the notification schedule
On the quarantine policies page, open the Quarantine notification settings flyout. You can set the notification to arrive every four hours, daily, or weekly.
Pick daily. Four hours is enough interruptions that people start ignoring it. Weekly is long enough that a real client email sits unread for six days.
While you're on that screen, use Specify sender address to set the sender to a real person at your firm. The default is quarantine@messaging.microsoft.com, which looks exactly like the kind of thing your staff have been trained to distrust. Use my company logo puts your branding at the top, which sounds cosmetic and isn't: this is a daily email with links in it, and people need to recognize it on sight. The logo has to be uploaded to your Microsoft 365 theme first. One trap on this screen: pick the language before you type anything into the sender display name, subject or disclaimer boxes, because selecting a language afterwards wipes what you typed.
Step 4: Turn off Outlook's own junk filter
Outlook has a separate junk filter that runs on the desktop, and it fights with the server. Microsoft's own recommendation is to set it to No automatic filtering, in Outlook under Home > Junk > Junk E-Mail Options > Options.
That doesn't disable anything you want. Safe Senders and Blocked Senders lists keep working. It just stops the desktop from making a second, different guess about mail the server already ruled on.
Step 5: Tell your team before it goes live
Do this the day before. The message they'll get from Microsoft is unfamiliar, it's about email, and it has links in it, which is the exact profile of a message you've spent years telling them not to click. Warn them or half of them will report the notification as phishing. There's a script for this in the setup pack below.
Step 6: Watch the queue for two weeks
Go to https://security.microsoft.com/quarantine daily for the first two weeks. You're looking for one thing: legitimate mail that got held. The same page is under Email & collaboration > Review > Quarantine if the direct link doesn't land.

Common catches at a firm:
Bank and lender notification emails, which are bulk-sent and often poorly authenticated
Payroll and portal notifications from smaller providers
A client whose own domain has a broken SPF record
Industry newsletters that cross the bulk threshold
Release what's legitimate. For a sender that keeps coming back, you want a real tenant-level allow, and this is the part that trips people up. The Allow sender button on a quarantined message adds that sender to the Safe Senders list of whoever is signed in, which is the same private per-mailbox list from earlier and not a firm-wide fix.
The tenant-level path runs through submissions. Go to https://security.microsoft.com/reportsubmission?viewid=email, submit the message as I've confirmed it's clean, and select Allow this message. That writes an allow entry for the sender into the Tenant Allow/Block List at https://security.microsoft.com/tenantAllowBlockList, where you can also add entries directly on the Domains & addresses tab. Those entries hold for 45 days after Microsoft's own filtering decides the sender is clean, or you can set them to expire up to 30 days out.
Keep that list short. Microsoft's warning is worth repeating: every unnecessary allow entry exposes you to mail the system would otherwise have filtered.
After two weeks you'll be down to a few minutes a week, and after a month you'll mostly forget it's there. The month-end issue made the same move on a close: the parts that keep running are the parts nobody has to open.
Standard or Strict: which preset to turn on
Strict quarantines everything, including ordinary spam and bulk mail, and drops the bulk threshold to 5.
Standard Strict
Spam Junk Quarantine
High confidence spam Quarantine Quarantine
Phishing Quarantine Quarantine
High confidence phishing Quarantine Quarantine
Bulk mail Junk Quarantine
Bulk threshold 6 5
Notification on Some verdicts All verdictsStart with Standard. Run it for two clean weeks. If the queue is quiet and nobody's complaining, move to Strict.
I'd expect a firm that goes straight to Strict with no quarantine history to spend day three releasing a pile of held mail and day five switching the whole thing off. Standard gets you most of the benefit with far fewer false positives.
One thing to know before you pick: retention differs. Under the default anti-spam policy, held mail lives 15 days and you can set that anywhere from 1 to 30. Under Standard or Strict it's 30 days and you can't change it. Thirty days is better. When mail expires from quarantine, Microsoft deletes it permanently, and there is no recovery.
What breaks, and what to do about it
A client's email gets held. Release it from the quarantine page. If it happens twice, take the submissions route above so the allow is firm-wide.
Someone says they never got the notification. Check that they're in scope. Scope the preset to specific recipients instead of All recipients and anybody outside that list is still living under the old default policy.
A staff member wants a high confidence phishing message released. They'll get a request option and you'll get the request. Look at it before you approve. That's Microsoft's highest-confidence bucket, and it's the one verdict users can never release on their own.
Your own outbound mail starts landing in clients' junk folders. Unrelated to any of this, and it means your SPF, DKIM or DMARC records need work. Go fix authentication.
You want to know how far off you were before. Run the configuration analyzer at https://security.microsoft.com/configurationAnalyzer. It lists every setting that doesn't match Standard, which is also the fastest way to find the custom policy somebody set up years ago that nobody remembers.
Do this week
Block thirty minutes. Open https://security.microsoft.com/presetSecurityPolicies, turn on Standard protection, apply it to all recipients, set the notification to daily, and send your team the message in the setup pack the day before it goes live.
If you only have ten minutes, do just the first part. The preset carries a working notification policy with it, so even the partial version still tells people what it held.
One question
Sometime in the first week, one thing is going to show up in that queue that you didn't expect. Something you'd have sworn was fine.
Which one was it? I'm building the list of what this catches that it shouldn't, because that list is my best guess at why firms turn quarantine back off, and there's no vendor page anywhere that will tell you what's on it.
The setup pack
Everything below is meant to be copied and used.
The rollout checklist
Work top to bottom. Nothing later depends on anything you skipped.
[ ] Confirm my role: Security Administrator or Organization Management
[ ] Check plan at admin.microsoft.com > Your products
[ ] Verify SPF, DKIM and DMARC on every domain we send from
[ ] Name the person who checks quarantine daily for 2 weeks
[ ] Send the team message (below), day before go-live
[ ] security.microsoft.com/presetSecurityPolicies > Standard protection > On
[ ] Manage protection settings > Exchange Online Protection > All recipients
[ ] Defender page (if licensed) > All recipients
[ ] Impersonation protection: add our domain, partners, anyone who approves payments
[ ] Review and confirm
[ ] security.microsoft.com/quarantinePolicies > Quarantine notification settings
[ ] Pick the language FIRST, then fill the text boxes
[ ] Notification frequency: Daily
[ ] Specify sender address: a real person here, not the Microsoft default
[ ] Use my company logo (upload to the Microsoft 365 theme first)
[ ] Outlook on every desktop: Junk > Junk E-Mail Options > Options > No automatic filtering
[ ] Calendar: check quarantine daily, 14 days
[ ] Calendar: 5 minutes weekly, ongoing
[ ] Day 14: run security.microsoft.com/configurationAnalyzer, confirm clean
[ ] Day 14: decide Standard or move to StrictThe message you send the team
Send it the day before. Subject line and body follow, and the placeholders in brackets are yours to fill.
Subject: New daily email from Microsoft starting tomorrow (this one is real)
Starting tomorrow you'll get an email once a day listing messages that got
held before they reached your inbox. It comes from [name and address you set
as the notification sender] and it will have our logo on it.
It's real. I turned it on.
Here's what changed. Until now, anything Microsoft thought was spam or
phishing went into your Junk folder, where you could still see it and open
it. It doesn't go there anymore. It gets held outside your mailbox, and the
daily email is how you find out what's in there.
If something legitimate got held, you can release it yourself from that
email. If it's a message flagged as a serious phishing attempt, you'll see
a request option instead. Send it to me and I'll look.
Two things I need from you:
1. Skim the daily list. It takes about thirty seconds.
2. If a client's email gets held, tell me the same day. I can allow that
sender for the whole firm so it stops happening.
Held mail is deleted after 30 days and can't be recovered, so don't leave
something sitting in there.
Questions to me, not to Microsoft.
[your name]The two-week watch routine
Same five minutes each morning until day fourteen. Log it as you go, one line per item.
Date: 12 Mar
Held overnight: 31
Legitimate, released: 2
- lender notification, [bank], released + submitted for a firm-wide allow
- client portal alert, [client], released, watching to see if it recurs
Phishing worth naming: 1
- request to change bank details, real company name in the subject
Actions taken: 1 allow submitted, nothing else
Team complaints: 0After fourteen days, look at the "legitimate, released" lines together. Fewer than three a week means you're in good shape and can consider Strict. More than ten a week and your email authentication is probably the real problem.
The weekly five minutes, forever
Open security.microsoft.com/quarantine
Sort by date, scan subject lines only
Release anything obviously legitimate
Note any sender held twice or more, submit it for a firm-wide allowA prompt for the part that's tedious
Reading a policy screen and working out which values don't match Microsoft's recommendations is slow, and it's the kind of comparison a model does well. It fails the busy test. You open this one on purpose, once, when you need it. The quarantine policy is the part that keeps working while you're busy.
Somebody set this policy up in 2022 and nobody has opened it since.
You are the one who opens the portal afterwards. This hands you a list and stops there, and every line on that list is a change you make with your own hands after you've read why.
I run a small accounting firm and I administer our own Microsoft 365. Below
is text I copied from an anti-spam policy screen in the Microsoft Defender
portal.
Work only from the text in the block. If a setting isn't in there, say
"not shown on this screen" rather than assuming what it is.
[paste the policy screen text here]
Give me three lists.
1. Settings where this policy is weaker than Microsoft's Standard
preset recommendation. For each one: the setting name, what it's set
to here, what Standard uses, and one plain sentence on what that
difference means for mail arriving at a firm that handles client tax
documents.
2. Settings where this policy is stricter than Standard. Same format.
I want to know these because stricter is not automatically better and
some of them will be why legitimate client mail is getting held.
3. Anything in the text that looks like it was set by hand for a reason
I'd want to remember before changing it.
Rank list 1 by what would reduce phishing reaching a mailbox the most.
Don't make the changes for me and don't give me PowerShell. I'm going to
do this in the portal so I can see what I'm agreeing to.Half an hour, and most of it is finding the page. It's at security.microsoft.com/presetSecurityPolicies, and it has been sitting there since you bought the licenses.


