Forum Discussion
File Sharing between licensed account holders
Licensing does not exempt a message from Defender filtering, so a legitimate sharing notification can be quarantined if its sender, URL, attachment, spoof signal, or policy produces a malware verdict. Open one recent example in the Microsoft Defender portal and inspect the email entity. Record the detection technology, threat type, policy, sender authentication, URLs, attachments, and overrides; this shows whether anti-malware caused the action. Verify the notification and shared file independently before release. If clean, submit the original quarantined message to Microsoft as a false positive and review the returned verdict. Use a temporary, narrowly scoped Tenant Allow/Block List entry only through that submission workflow if continuity requires it. Do not create a broad transport-rule bypass for Microsoft domains or sharing messages, because other entities would evade filtering. Compare several affected messages to find the common detected entity; if submissions remain misclassified, open Microsoft support with message IDs and results.