Fix Teams File Is Quarantined by Defender for a Guest Conversation
🔍 WiseChecker

Fix Teams File Is Quarantined by Defender for a Guest Conversation

When you share a file in a Teams guest conversation, Microsoft Defender for Office 365 may quarantine it. The file becomes unavailable, and both you and the guest see an error. This happens because Defender scans files shared in external or guest contexts with stricter policies. This article explains why Defender quarantines files in guest conversations and how to fix it from the Defender portal and Teams admin center.

You will learn the exact steps to release a quarantined file, adjust quarantine policies, and prevent future blocks. The fix involves checking the quarantine queue, modifying policy settings, and verifying that guest sharing is allowed. After following these steps, your files will flow normally in guest conversations.

Key Takeaways: Fixing Quarantined Files in Teams Guest Conversations

  • Microsoft 365 Defender portal > Email & collaboration > Review > Quarantine: Locate and release files quarantined by Defender for Office 365.
  • Microsoft 365 Defender portal > Email & collaboration > Policies & rules > Threat policies > Quarantine policies: Adjust the action taken on files shared in guest conversations.
  • Teams admin center > Org-wide settings > Guest access: Ensure guest access is enabled so files are not blocked by policy.

ADVERTISEMENT

Why Defender Quarantines Files in Guest Conversations

Microsoft Defender for Office 365 scans all files shared through Teams, including those in conversations with external guests. The scanning engine uses the same threat intelligence that protects email attachments. When a file is shared in a guest conversation, it is treated as external content. This triggers a higher security threshold because the sender and recipient are not in the same organization. Any file that matches a malware signature, a suspicious URL, or a policy rule is moved to quarantine.

The quarantine action is defined by the quarantine policy assigned to the protection profile. By default, the policy may be set to quarantine files that contain links or attachments. In guest conversations, the policy may also block files that are encrypted or password-protected because they cannot be scanned. The result is that the file does not appear in the conversation, and users see a message that the file was removed or blocked.

Another factor is the tenant configuration for guest access. If guest access is disabled or restricted, Teams may block file sharing entirely. Even if guest access is enabled, the file goes through the same Defender pipeline as email. The quarantine decision is made before the file reaches the conversation. Therefore, the fix requires action in both the Defender portal and the Teams admin center.

How the Quarantine Process Works

When a user shares a file, Teams uploads it to SharePoint and sends a link to the conversation. Defender for Office 365 scans the link and the file content. If the scan finds a threat, the link is replaced with a message that the file is quarantined. The original file remains in SharePoint, but the link is blocked. The quarantine record appears in the Defender quarantine queue, where an admin can review and release it.

Steps to Release and Prevent Quarantined Files in Guest Conversations

Follow these steps to fix the issue. You need to be a global admin or a security admin to access the Defender portal and the Teams admin center.

  1. Open the Microsoft 365 Defender quarantine queue
    Go to the Microsoft 365 Defender portal at security.microsoft.com. Select Email & collaboration, then Review, then Quarantine. This page shows all quarantined items, including files from Teams.
  2. Filter the quarantine list for Teams files
    Use the filter option to show only items with the source Teams. Select the filter icon, choose Source, and pick Teams. You will see all files that were quarantined from Teams conversations.
  3. Identify the quarantined file
    Look for the file name and the guest user. The quarantine record shows the original sender, the recipient, and the reason for quarantine. If the reason is Malware or High confidence phishing, the file is likely infected. If the reason is Policy, it was blocked by a rule.
  4. Release the file from quarantine
    Select the file and click Release. Confirm the action. The file becomes available again in the Teams conversation. If you want to report a false positive, click Submit to Microsoft for analysis before releasing.
  5. Check the quarantine policy settings
    In the Defender portal, go to Email & collaboration, then Policies & rules, then Threat policies, then Quarantine policies. Review the policy that applies to Teams. If the action is set to Quarantine, change it to Deliver or Allow for safe file types. Save the policy.
  6. Verify guest access in Teams
    Go to the Teams admin center at admin.teams.microsoft.com. Select Org-wide settings, then Guest access. Ensure the toggle for Allow guest access in Teams is set to On. Also check that Share files is enabled under the guest permissions section.
  7. Test the file sharing again
    Ask the user to share a new file in the same guest conversation. The file should appear without a quarantine message. If the issue persists, check the audit log in the Defender portal for the specific file.

Adjusting the Quarantine Policy for Safe Files

If you have a policy that quarantines files based on file type, you can create an exception. In the quarantine policy settings, add an allow entry for the file extension or the sender domain. This prevents the policy from blocking files that are safe. Use this only for trusted file types and senders.

ADVERTISEMENT

If Teams Still Has Issues After the Main Fix

Sometimes the quarantine message remains even after you release the file. This can happen because the policy is still active or because the file was blocked by another rule. Here are the most common remaining problems and their fixes.

Teams Shows a Message That the File Was Removed

If the file still shows as removed, check the SharePoint site where the file is stored. The file may have been deleted by a data loss prevention policy. Go to the SharePoint site and verify that the file exists. If it was deleted, restore it from the SharePoint recycle bin.

The Quarantine Policy Blocks All Files From Guests

This happens when the policy applies to all external content. Create a new quarantine policy that allows files from guests. In the Defender portal, go to Threat policies, then Anti-malware. Edit the policy and add an exception for guest users or for the guest domain.

Guest Users Cannot See the Released File

After you release a file, the guest may need to refresh the conversation. Ask the guest to close and reopen the Teams chat. If the file still does not appear, the guest may not have permission to access the SharePoint site. Check the sharing settings in SharePoint and ensure that the guest has the correct link permissions.

Defender Quarantine vs Teams Guest Sharing: Key Differences

Item Defender Quarantine Teams Guest Sharing
Purpose Protect against malware and phishing Allow external users to access files
Admin portal Microsoft 365 Defender portal Teams admin center
Action Blocks the file link Controls whether sharing is allowed at all
Configurable Yes, via quarantine policies Yes, via guest access settings
Default behavior Quarantine suspicious files Guest access is off by default

Now you can release quarantined files from guest conversations and adjust the policies that cause the block. Start by releasing the specific file from the Defender quarantine queue. Then review your quarantine policy and guest access settings to prevent future blocks. For advanced protection, create a custom quarantine policy that allows safe file types from trusted guest domains.

ADVERTISEMENT