Blog Post

Microsoft Defender for Office 365 Blog
2 MIN READ

Simplifying the Quarantine Experience - Part Two

FaithEbenezerOquong's avatar
May 12, 2022

Managing false positives should be easy

In the previous blog we talked about some of the key steps we took to make the quarantined experience simpler for our end users and admins. Here in part two, we will be highlighting additional features we’re introducing to make the quarantine experience even more easy to use.

 

Exciting new updates are coming soon!

Microsoft Defender for Office 365 is rolling out key quarantine management features that will help empower SecOps professionals and end user when triaging emails:

  • "Within 4 hours" option for notifications
  • Password protected download of quarantined messages
  • Asynchronous quarantine experience – database migration.

 

"Within 4 hours" option for notifications

We have heard from customers that they desire granular options when it comes to end user email notifications. We’re adding a new "within 4 hours" option to end user notifications, allowing users to be able to rely on prompt notification about quarantined items when appropriate. With this feature users can be rest assured that they will be updated frequently once new items lands on their quarantine folder.     

 

 

 

Password protected download of quarantined messages

With this change we’re giving the ability to password protects items they download from quarantine. We want users to be confident that the items they are downloading to their systems will not execute involuntarily without their consent, and this capability will allow them to safely transport the items to external analysis tools.  

 

 

 

Additional updates to support search and larger bulk operations

 

Microsoft Defender for Office 365 is working to enable additional quarantine enhancements, like partial string search functionality and 1,000 message bulk operation support in quarantine. As a result, we'll be making adjustments to the release process through an asynchronous approach.

 

What does an asynchronous approach mean for me?

With the asynchronous approach, we're able to support bulk operations up to 1,000 messages, and these larger requests may take longer to process. As a result, we'll be introducing additional statuses for quarantined messages, like “Preparing to release” and “Error”. The “Preparing to release” status will indicate that the messages is in the process of being released while the “Error” status will indicate that a message release has failed, and the user needs to retry.

 

Let us know what you think!

Test out these new capabilities when they begin rolling out in the next couple months and let us know any feedback you may have. We’re always looking for ways to improve the quarantine experience for users and admins.

 

 

Do you have questions or feedback about Microsoft Defender for Office 365? Engage with the community and Microsoft experts in the Defender for Office 365 forum.

 

 

Updated Mar 08, 2023
Version 3.0

68 Comments

  • DaithiG's avatar
    DaithiG
    Iron Contributor

    Is there a time line for GA for these features, particularly the hourly notifications

  • chrislehr's avatar
    chrislehr
    Copper Contributor

    Are the notification options staying as "Global Settings" or can we have different notification settings per policy?  I've never understood why this went to Global as end users have differing needs.

  • I have two questions.  First, what is meant by the term  Time Travel?  As in...

    In the case of Time travel, where malicious items need to be zapped from inbox to quarantine but there is no space, these messages will be instead, added to the junk mail folder.

    My second question is...what is the size of the user's quarantine?  As in...

    In the case that a user’s quarantine storage is full...

  • DaithiG's avatar
    DaithiG
    Iron Contributor

    I like the hourly notification. We're using the Junk Email folder but with the hourly notification, I'd almost stop using that and let the Quarantine notification email handle it. People always complain they forget to check their Junk Email (and legitimate email is going there too much for people)

  • a-yates's avatar
    a-yates
    Brass Contributor

    On the anti-malware policy you can currently enable notification to the user when message is blocked and they actually still get the message, but minus the attachments. But this is being deprecated in favour of the Quarantine notifications.

    One useful feature with this legacy notification, is that it allowed the original message to come through minus the attachments.

     

    Once this legacy feature is removed and we have to use Quarantine notifications only, there is no method to release a legitimate message, minus that attachment. So I'm not actually going to want to notify the user or give them or support the opportunity to release because although I don't mind them getting the email, I don't want them to have the attachment in case it contains some unknown malicious content.

    So it would be good to still have some method where we can allow messages to pass through the original message, minus the attachment and/or allow option in Quarantine to release message without attachment. Even better make it so that you can only release the message without attachment for specific group of people, so users can only release without attachment but admins could release with attachment after additional checks done.

  • MSFrodo's avatar
    MSFrodo
    Former Employee

    It would be great to control the time zone and the specific "time after 2PM" to get the notification send. 

  • Adin_Calkic's avatar
    Adin_Calkic
    Iron Contributor

    This is great improvement. Especially Hourly option for notification.