Skip to content

Microsoft 365 Quarantine integration

The Quarantine in Microsoft 365 rule response adds each lookalike domain a matched rule cites to the Exchange Online Tenant Allow/Block List as a sender block that expires after 30 days. Exchange Online marks mail from a blocked sender as high confidence phishing and quarantines it. The rule decides which alerts trigger the response. Connecting a tenant alone blocks nothing.

  • Exchange Online, with or without Microsoft Defender for Office 365.
  • A Global Administrator, Privileged Role Administrator, or Cloud Application Administrator in Microsoft Entra ID to grant admin consent and assign a role.
  • The network enforcement add-on on the Have I Been Squatted organization, and an organization admin to configure it.

Have I Been Squatted uses one multi-tenant Microsoft Entra application for this integration, Have I Been Squatted - Email Response. It is separate from the Microsoft 365 Email Intelligence and Defender for Endpoint applications. Consent grants it:

Permission API Type Purpose
Exchange.ManageAsApp Office 365 Exchange Online Application Run Exchange Online commands
User.Read Microsoft Graph Delegated Sign-in only, to identify the tenant and its initial domain

Exchange.ManageAsApp lets the application call Exchange Online, but Exchange only runs a command that a role assigned to the application allows. The application has no read access to mail, mailboxes, or other Microsoft 365 data.

The customer supplies no credential. Have I Been Squatted authenticates with its own application secret and requests a short-lived token for the tenant on each delivery.

  1. In the app, open Connectors > Microsoft 365 Quarantine.
  2. Select Connect tenant and sign in as an administrator who can grant admin consent.
  3. Review the requested permissions and accept them on behalf of the organization.
  4. Assign the application a role, as described in the next section.
  5. On the settings page, optionally add Protected domains.
  6. Select Test connection.

The tenant is taken from the verified identity token of the administrator who signed in, never from the address bar. A Microsoft tenant can be connected to only one Have I Been Squatted organization.

Exchange Online routes each request through the tenant’s initial domain, for example contoso.onmicrosoft.com. Have I Been Squatted reads it from Microsoft Graph during sign-in, using the User.Read permission. If it can’t, enter it on the settings page; it is listed in the Microsoft 365 admin center under Settings > Domains.

Exchange Online requires the application to hold a role that can manage the Tenant Allow/Block List. In the Microsoft Entra admin center, open Roles & admins, select Security Administrator, choose Add assignments, and select Have I Been Squatted - Email Response.

Security Administrator is the narrowest Microsoft Entra role supported for Exchange Online application access that can manage the Tenant Allow/Block List. Role assignments can take a few minutes to reach Exchange Online.

The check requests the same token delivery uses and reads the Tenant Allow/Block List through Exchange Online. Blocking stays off until a check passes. Changing the Exchange organization turns blocking off until the next check passes.

The check reads the list and never changes it, so it can’t prove that the role allows writing. A read-only role such as Security Reader passes the check, and deliveries then fail with a permission error.

Result Meaning
Consent missing Microsoft has not granted admin consent for the tenant yet, or the application was removed. Test again after a few minutes, then reconnect if it persists.
Authentication Exchange Online did not accept the application’s token. Reconnect with an administrator who can grant admin consent.
Role missing The application has no role that manages the Tenant Allow/Block List. Assign Security Administrator as described above, then test again.
Organization not found Exchange Online did not find the organization. Check that it is the tenant’s initial .onmicrosoft.com domain and that the tenant has Exchange Online.
Unreachable Microsoft timed out, throttled the request, or returned a server error. Test again later.
Configuration The Have I Been Squatted application credential was rejected. This is a platform problem; contact support.

A failed check pauses blocking until a later check passes. Consent and authentication failures mark the connection as needing reauthorization.

Protected domains are optional. Have I Been Squatted never blocks a protected domain or any of its subdomains, whatever a rule cites. Rules already skip lookup results tagged owned, ignored, or false positive, unless the result also carries another tag such as malicious. Use this list for partners and other domains your users exchange mail with. Protected domains apply to new deliveries as soon as they are saved.

  1. Create or edit a rule and open the Response tab.
  2. Select Add action > Quarantine in Microsoft 365.
  3. Select the Microsoft 365 destination.
  4. Save the rule.

The destination is listed only after a connection check has passed. The response needs at least one domain condition in the rule, because only cited lookalike domain records produce blocks.

For each active rule alert that cites lookalike domain records, Have I Been Squatted handles each distinct cited domain, up to 10 per alert:

Existing entry for the domain Action
None Create a sender block for 30 days
An allow entry Leave it; nothing is blocked
A block entry the tenant created Leave it unchanged
A block entry from Have I Been Squatted, 15+ days left Leave it unchanged
A block entry from Have I Been Squatted, under 15 days Renew it for 30 days
A block entry from Have I Been Squatted set never to expire Leave it unchanged

Entries from Have I Been Squatted carry the note Have I Been Squatted rule <rule ID> alert <alert ID>, which is how they are recognized. Entries written by the retired Email Intelligence Watchdog count as well.

  • Only domains from cited domain (lookalike permutation) records are sent.
  • The monitored domain, its subdomains, and protected domains are never blocked.
  • A block covers exactly the cited domain. A block on examp1e.com doesn’t cover mail.examp1e.com; a cited subdomain gets its own entry.
  • No email content, addresses, or other alert data is sent.

If Exchange refuses one domain, the others are still processed. If Microsoft times out, returns a server error, or rejects the token or role, the remaining domains are not processed and the delivery is not retried.

Have I Been Squatted stores the connected tenant ID, the consent time, the Exchange organization, the protected domains, and the time and outcome of the last connection check. For each alert and response, it records the delivery status, the domains it blocked, renewed, or left alone and why, the expiry, and, when a delivery fails, a short error code. Access tokens and Microsoft response bodies are not stored.

Disable stops new blocks and keeps the connection, its settings, and rule responses. A passing connection test turns blocking back on.

Disconnect removes the connection, its settings, and the Quarantine in Microsoft 365 response from every rule. The tenant can then be connected to another organization.

Neither action removes entries already in the Tenant Allow/Block List. They stay until they expire, within 30 days, or until an administrator removes them in the Microsoft Defender portal.

Disconnecting does not revoke the consent or the role. To remove the application’s access, remove its Security Administrator assignment and delete Have I Been Squatted - Email Response under Enterprise applications in the Microsoft Entra admin center. Deliveries and connection checks then fail with missing consent.

  • The Tenant Allow/Block List holds at most 500 sender block entries without Defender for Office 365, 1,000 with Plan 1, and 10,000 with Plan 2. Blocks from Have I Been Squatted count toward that limit, together with the tenant’s own entries.
  • An entry takes up to five minutes to take effect.
  • The integration uses the Microsoft global cloud. Sovereign clouds such as GCC High and DoD are not supported.