When you upload a file to a Microsoft Teams private channel, Microsoft Defender for Office 365 may quarantine it. This happens because private channel files are stored in a separate SharePoint site that inherits a default data loss prevention policy. The result is a blocked file that users cannot open or share. This article explains why Defender flags these files and how to release them from quarantine permanently.
You will learn the exact steps to locate the quarantined file in the Defender portal, submit it for release, and adjust the policy so future uploads are not blocked. The fix applies to files uploaded to private channel tabs, posts, or the Files tab. The same process works for files that Defender quarantined automatically or after a user report.
Key Takeaways: Releasing Quarantined Files in Teams Private Channels
- Microsoft 365 Defender portal > Email & collaboration > Review > Quarantine: Shows all quarantined files, including those from private channel SharePoint sites.
- Quarantine details > Release message: Restores the file to the original private channel location.
- Tenant Allow/Block Lists > File hash: Prevents Defender from quarantining the same file hash again.
Why Microsoft Defender Quarantines Files in a Private Channel
Microsoft Teams private channels create their own SharePoint site collection. This site is separate from the main team site and has its own document library. Defender for Office 365 applies Safe Attachments and anti-malware policies to all SharePoint files, including those in private channel sites. When a file matches a suspicious signature, Defender moves it to quarantine instead of blocking the upload entirely.
The quarantine action is not a user error. It is a security response triggered by file content, file hash, or file extension. Common triggers include macro-enabled Office files, executable files, or files that contain a known malicious pattern. A file can also be quarantined if a user reports it as phishing or malware using the user reporting feature.
Private channels have a unique problem. The quarantine notification in Teams does not always appear in the activity feed. Users see a broken file icon or a message that says the file is blocked. The file is still present in the SharePoint library but marked as quarantined. Only an admin with access to the Defender portal can release it.
Steps to Release a Quarantined File in a Private Channel
You need Global Administrator or Security Administrator permissions to perform these steps. If you do not have these roles, ask your Microsoft 365 admin for help.
- Open the Microsoft 365 Defender portal
Go to security.microsoft.com and sign in with your admin account. If the portal opens to the home page, select Email & collaboration from the left navigation. - Navigate to the Quarantine page
In the left navigation, select Review, then select Quarantine. The quarantine list shows all quarantined items across Exchange, SharePoint, and Teams. - Filter for SharePoint files
At the top of the quarantine list, select the Filter button. Choose SharePoint from the workload dropdown. This shows only files quarantined from SharePoint sites, which includes all Teams private channel files. - Locate the quarantined file
Look for the file name in the list. The Recipient column shows the SharePoint site name, which often contains the private channel name. If you have many files, use the search box and type the file name or part of it. - Open the file details
Select the checkbox next to the file, then select View quarantine details from the toolbar. The details pane shows the original location, the detection reason, and the file hash. - Release the file
In the details pane, select Release message. A confirmation dialog appears. Select Release again. The file is restored to the original private channel document library within a few minutes. - Verify the file in Teams
Go back to the Teams private channel and open the Files tab. The file now shows a normal icon and can be opened. If the file still shows as blocked, wait 10 minutes and refresh the page.
If the File Does Not Appear in the Quarantine List
Sometimes the file is quarantined at the SharePoint level but not visible in the Defender portal. In that case, use SharePoint admin center to release it. Go to admin.microsoft.com/SharePoint, select Active sites, and find the private channel site. The site name usually contains the team name and the channel name, separated by a dash. Select the site, then select Quarantine from the top menu. Find your file and select Release.
If Teams Still Has Issues After the Main Fix
Releasing the file once does not stop Defender from quarantining it again. If the same file is uploaded again or if a user edits and re-saves it, Defender may flag it again. Use the following methods to prevent repeat quarantine.
Teams File Is Quarantined Again After Release
This happens when the file hash is still on the tenant allow/block list. To prevent future quarantine, add the file hash to the allow list. In the Defender portal, go to Email & collaboration > Policies & rules > Threat policies > Tenant Allow/Block Lists. Select the File hash tab, then select Add. Enter the file hash from the quarantine details and set the expiration to Never. This stops Defender from blocking that exact file.
Users Cannot Download a Quarantined File in a Private Channel
If the file is in the quarantine list but users still cannot download it, the issue is a SharePoint permission problem. Private channel sites have unique permissions. Check that the channel owner and members have at least Contribute permission. Go to the SharePoint site, select Site permissions, and verify the channel members group exists. If not, add the group manually.
Defender Quarantines a File That Is Safe in a Private Channel
If the file is a false positive, submit it to Microsoft for analysis. In the Defender portal, select the quarantined file, then select Submit to Microsoft for analysis. Choose Clean and provide a brief explanation. Microsoft reviews the file and may update the policy. This does not release the file automatically. You still need to release it after the submission.
Quarantine in Private Channels vs Standard Channels: Key Differences
| Item | Private Channel | Standard Channel |
|---|---|---|
| Storage location | Separate SharePoint site per channel | Shared SharePoint site for the team |
| Quarantine visibility | May not appear in Teams activity feed | Shows in the team site document library |
| Release method | Defender portal or SharePoint admin center | Defender portal or SharePoint admin center |
| Permission inheritance | Unique permissions, not inherited from team | Inherited from team site permissions |
Conclusion
Releasing a quarantined file in a Teams private channel is a two-step process. First, locate the file in the Microsoft 365 Defender portal under Quarantine. Second, use the Release message action to restore it. After release, add the file hash to the Tenant Allow/Block Lists to prevent the same file from being blocked again. If the file still has issues, check SharePoint site permissions or submit a false positive report to Microsoft. Use the SharePoint admin center as a backup method when the file is not visible in Defender.