Fix Teams File Is Quarantined by Defender after a Compliance Policy Change
🔍 WiseChecker

Fix Teams File Is Quarantined by Defender after a Compliance Policy Change

You see a notification that a file you shared or uploaded in Teams has been quarantined by Microsoft Defender for Endpoint after your organization changed a compliance policy. The file is blocked from viewing, downloading, or sharing, which interrupts your team’s work. This happens because the new policy applies stricter threat detection rules, and Defender may flag files that were previously allowed. In this article, you will learn why the quarantine occurs, how to release the file and adjust the policy, and what to do if the issue persists.

Key Takeaways: Fixing Quarantined Teams Files After a Policy Change

  • Microsoft Defender for Endpoint > Actions > Quarantine: View and release files that Defender has blocked in Teams.
  • Microsoft 365 Defender > Policies > Rules > Quarantine policies: Adjust or create exceptions for legitimate file types or users.
  • Teams admin center > Teams apps > Manage apps: Verify that the Teams app version and file handling settings are compatible with your compliance policy.

ADVERTISEMENT

Why Defender Quarantines a Teams File After a Compliance Policy Change

When your organization updates a compliance policy, it often changes how files are scanned and classified. Microsoft Defender for Endpoint uses these policies to decide whether a file is safe. If the policy becomes more restrictive, Defender may quarantine files that contain macros, encrypted content, or scripts that look suspicious. The quarantine action moves the file to a secure location, removing it from your Teams channel or chat.

The root cause is a mismatch between the new policy’s threat detection rules and the file’s characteristics. For example, a policy that blocks executable attachments will quarantine a .exe file even if it is a legitimate installer. Similarly, a policy that flags files with certain metadata or digital signatures can block files that were previously shared without issue.

Another factor is the file’s origin. If the file was uploaded by an external user or came from a SharePoint site that is not trusted, Defender may apply a higher risk level. The compliance policy change can also affect how Teams interacts with SharePoint and OneDrive, because Teams files are stored in those services.

How the Compliance Policy Affects Teams File Storage

Teams stores files in SharePoint or OneDrive, and Defender scans these files when they are uploaded or accessed. A compliance policy change can alter the default sharing links, retention labels, or data loss prevention rules. These changes can trigger Defender to re-scan files and apply a new verdict. If the file fails the scan, it is quarantined immediately.

Steps to Release a Quarantined Teams File and Adjust the Policy

Follow these steps to restore access to the quarantined file and prevent future occurrences. You need appropriate permissions: Security Administrator or Global Administrator in Microsoft 365 Defender, and Teams Administrator for policy changes.

  1. Open Microsoft 365 Defender portal
    Go to security.microsoft.com and sign in with your admin account. This is the central place for Defender actions.
  2. Navigate to the Quarantine page
    Select Actions & submissions in the left navigation, then choose Quarantine. Alternatively, use the search bar and type “Quarantine”.
  3. Find the quarantined file
    Use the filter options to search by file name, upload date, or the user who uploaded it. Look for the file that was quarantined after the policy change.
  4. Review the threat details
    Click the file to open its details page. Check the threat name, the policy that triggered the quarantine, and the detection time. This helps you verify whether the file is truly malicious.
  5. Release the file if it is safe
    If the file is legitimate, select Release on the details page. Confirm the action in the dialog. Defender will restore the file to its original location in Teams, SharePoint, or OneDrive.
  6. Notify the affected user
    After releasing, inform the user who shared the file. They may need to refresh their Teams client to see the file again.
  7. Adjust the compliance policy to prevent recurrence
    Go to Microsoft 365 Defender > Policies > Rules. Locate the compliance policy that changed. Edit the policy to add an exception for the file type or the specific file, or for the user or group that shares such files. Save the changes.
  8. Test with a similar file
    Upload a test file with the same characteristics to confirm the policy now allows it. If the test file is still quarantined, the exception may not be applied correctly.

Adjusting Quarantine Policies in Microsoft 365 Defender

If you cannot modify the compliance policy directly, you can create a custom quarantine policy. Go to Policies > Rules > Quarantine policies and create a new policy that defines which file types are allowed. Apply this policy to the relevant users or groups. This gives you granular control over what Defender blocks.

ADVERTISEMENT

If Teams Still Has Issues After the Main Fix

Teams Shows the File as Blocked Even After Release

This can happen if the file is cached in the Teams client. Ask the user to sign out of Teams and sign back in, or clear the Teams cache. On Windows, close Teams, delete the %appdata%\Microsoft\Teams folder contents, and restart Teams.

The File Is Quarantined Again After Release

The policy may still be too strict, or the file may contain a pattern that Defender flags repeatedly. Check the threat name. If it is a false positive, submit the file to Microsoft for analysis. In Defender, go to Actions & submissions > Submissions and submit the file as a false positive.

Users Cannot Upload Files to Teams at All

This is broader than a single file issue. Verify that the compliance policy does not block uploads from certain locations or devices. Also check the SharePoint admin center for sharing settings. If the policy blocks all file types, you need to revise it to allow common document formats like .docx, .xlsx, and .pdf.

Defender Quarantines Files in Private Channels

Private channels have separate SharePoint sites. The compliance policy may apply differently to these sites. Check the site’s sharing permissions and ensure the policy covers the site. You may need to add an exception for the private channel’s site URL.

Defender Quarantine vs Compliance Policy Exceptions: Key Differences

Item Defender Quarantine Compliance Policy Exception
Purpose Isolates suspicious files for security Allows specific files or users to bypass blocking
Effect Removes file from Teams until released Prevents quarantine from happening
Where to configure Microsoft 365 Defender > Quarantine Microsoft 365 Defender > Policies > Rules
Best for One-time false positives Ongoing legitimate file types

ADVERTISEMENT

Conclusion

You can now release quarantined Teams files from the Microsoft 365 Defender portal and adjust compliance policies to prevent future blocks. Start by reviewing the quarantine details to confirm the file is safe, then release it and notify the user. Next, create an exception in the relevant policy or a custom quarantine policy for legitimate file types. To avoid repeated issues, always test policy changes with sample files before applying them broadly. Use the Actions & submissions page to submit false positives to Microsoft for faster resolution.

ADVERTISEMENT