Fix Teams File Is Quarantined by Defender for a Recorded Meeting
🔍 WiseChecker

Fix Teams File Is Quarantined by Defender for a Recorded Meeting

When you record a Teams meeting, the recording is saved as an MP4 file. Sometimes Microsoft Defender for Endpoint flags that file as a threat and quarantines it. You see an error that the file is quarantined, and you cannot open or recover the recording. This happens because Defender scans the file and falsely detects a virus signature. This article explains why the file gets quarantined and how to restore it safely.

You will learn how to check the Defender portal, restore the file, and add an exclusion to prevent future false positives. You will also see what to do if the file is permanently deleted or if the quarantine happens on a local device.

Key Takeaways: Restore a Quarantined Teams Recording

  • Microsoft Defender portal > Endpoint > Investigation > Quarantine: Shows all quarantined files and lets you restore a falsely detected recording.
  • Microsoft Defender portal > Settings > Endpoints > Indicators: Adds a file hash exclusion so Defender stops flagging the recording file.
  • Windows Security > Virus & threat protection > Protection history: Restores a quarantined file on a local device where Teams saved the recording.

ADVERTISEMENT

Why Defender Quarantines a Teams Meeting Recording

Microsoft Defender for Endpoint scans every file that Teams uploads or downloads. The scanning engine uses signature-based detection and heuristic analysis. A recorded meeting MP4 file can contain a metadata structure that resembles a known threat pattern. This false positive triggers the quarantine action. The file is moved to a secure storage area and blocked from normal access.

Another cause is the file hash. If the hash of your recording matches a hash that Defender has flagged in a global threat list, the file is quarantined even if it is clean. This happens when the recording was generated by a third-party tool that adds unusual metadata. Defender does not distinguish between a real threat and a benign file with a matching hash.

When the file is quarantined, Teams shows an error message. The error may appear in the chat, in the meeting details, or in the Stream portal. The file is not deleted but is inaccessible. You must restore it from the Defender portal or from the local quarantine list.

Where Quarantined Files Are Stored

For cloud recordings, the file is stored in the Defender for Endpoint quarantine area. For local recordings, the file is stored in the Windows Security quarantine folder. The location depends on how you recorded the meeting. Teams desktop recordings are cloud recordings. Teams on the web may save a local recording if you use the built-in recorder.

Steps to Restore a Quarantined Teams Recording

Follow these steps to restore a falsely quarantined recording. You need permission to access the Microsoft Defender portal. If you are a global admin or a security admin, you can complete the restore.

  1. Open the Microsoft Defender portal
    Go to security.microsoft.com and sign in with your admin account. If you do not have admin rights, ask your IT administrator to perform the restore.
  2. Go to the Quarantine page
    In the left navigation, select Endpoint > Investigation > Quarantine. This page lists all files that Defender has isolated.
  3. Find your recording file
    Use the search box to enter the file name or the file hash. The file name usually contains the meeting subject and a timestamp. Look for the file with the MP4 extension.
  4. Select the file and choose Restore
    Click the checkbox next to the file, then click Restore. Confirm the action when prompted. The file is moved back to its original location.
  5. Check the file in Teams
    Go to Teams and open the chat or channel where the recording was posted. Refresh the page. The recording should now be playable.

ADVERTISEMENT

Steps to Add an Exclusion for the Recording File

To prevent Defender from quarantining the same file again, add an exclusion for the file hash or the file extension. This step is optional but recommended if you record meetings frequently.

  1. Open the Indicators page
    In the Microsoft Defender portal, go to Settings > Endpoints > Indicators.
  2. Create a new indicator
    Click Add indicator. Choose File hash as the indicator type.
  3. Enter the file hash
    Copy the SHA256 hash of the quarantined file from the Quarantine page. Paste it into the hash field.
  4. Set the action to Allow
    In the Action section, select Allow. Set the scope to all devices or a specific device group.
  5. Save the indicator
    Click Save. The exclusion takes effect within a few minutes. Then restore the file again if needed.

If the Recording Was Quarantined on a Local Device

If you recorded the meeting locally, the file may be quarantined by Windows Security. To restore it, follow these steps.

  1. Open Windows Security
    Click the Start button, type Windows Security, and press Enter.
  2. Go to Protection history
    Select Virus & threat protection, then click Protection history.
  3. Find the quarantined item
    Look for an entry that shows the recording file name and the status Quarantined.
  4. Restore the file
    Click the drop-down arrow next to the item, then click Restore. The file is returned to its original folder.
  5. Open the recording
    Navigate to the folder where Teams saves local recordings. The default folder is Documents > Teams Recordings. Double-click the file to play it.

ADVERTISEMENT

If Teams Still Shows the Quarantine Error After Restoring

Sometimes the error persists even after you restore the file. This happens when the Teams client has cached the threat status. Clear the Teams cache and refresh the page.

Teams Shows a Quarantine Error in the Chat Window

Close Teams completely. Press Ctrl+Alt+Delete and open Task Manager. End all processes named Teams. Then restart Teams. The chat should refresh and show the restored recording.

The Recording Is Permanently Deleted

If Defender deleted the file instead of quarantining it, you cannot restore it from the portal. Check the recycle bin in SharePoint or OneDrive. The recording is stored in the Recordings folder in the OneDrive of the meeting organizer. If the file is not there, you must re-record the meeting.

Defender Blocks the File Every Time You Upload It

If you upload the same recording again, Defender may quarantine it again. Add a file hash exclusion as described above. If the hash changes after each upload, use an extension exclusion for MP4 files. Be careful with extension exclusions because they reduce security for all MP4 files on the device.

Teams Cloud Recording vs Local Recording: Quarantine Behavior

Item Cloud Recording Local Recording
Storage location OneDrive or SharePoint Documents > Teams Recordings
Quarantine location Microsoft Defender portal Windows Security quarantine
Restore method Defender portal > Quarantine Windows Security > Protection history
Exclusion method Defender portal > Indicators Windows Security > Exclusions
Admin rights needed Yes No, if you are the device owner
Risk of permanent deletion Low Medium, if the file is not restored quickly

Conclusion

You can now restore a Teams meeting recording that Defender quarantined. Use the Microsoft Defender portal for cloud recordings or Windows Security for local files. Add a file hash exclusion to stop future false positives. If the file is permanently deleted, check the OneDrive recycle bin. For frequent false positives, create an extension exclusion for MP4 files. Always verify the file is safe before you open it.

ADVERTISEMENT