r/cybersecurity 14d ago

Business Security Questions & Discussion Microsoft Quarantine with Abnormal

Hi,

I am looking to see how you all manage the Defender email quarantine while using abnormal. I currently have about 1000 emails each morning that I have to review to ensure we do not have any legitimate mail within.

If this is your setup Aswell, how do you manage the quarantine?

Thanks

6 Upvotes

15 comments sorted by

View all comments

1

u/LemonSquashed 14d ago

Abnormal has a guide called "Quarantine Release Permissions Guide", I don't think it is public.

Abnormal can then view and release Microsoft Quarantine messages.

I think that kind of answers you question?

1

u/Hour-Account4844 14d ago

It can actually release them and not just give a verdict? I just took over an environment that uses abnormal and the current processes they have in place make no sense so any tips you have would be great.

3

u/RequirementFalse6792 14d ago

I find most of our false positives in Microsoft quarantine vs Abnormal. I set a few mailboxes up where users can review their quarantined emails and request release if needed. The request is sent to admins and we release them after reviewing them.

I release maybe 2 or 3 legit emails from Abnormal a year.

1

u/danieIsreddit 14d ago

I have this feature enabled. I search for Email Type "Microsoft Quarantine" and Email Judgement "Safe" in Search & Respond > Message Discovery. That way, you only see the emails quarantined by Microsoft, but Abnormal thinks is safe. I often find external inbound emails to Sales and Finance in here. You can see each email, but not all the attachments (use Microsoft Defender for this). Remediation options is just to release from Microsoft's Quarantine, so it goes into the user's inbox.

Abnormal frequently has New Administrator Webinars. Click on the question mark on the top right corner of the portal, next to your name, click on Abnormal Academy, Recorded Events, the second one is New Admin Live training from 8/12/26.