Microsoft 365 Quarantine integration
The Quarantine in Microsoft 365 rule response adds each lookalike domain a matched rule cites to the Exchange Online Tenant Allow/Block List as a sender block that expires after 30 days. Exchange Online marks mail from a blocked sender as high confidence phishing and quarantines it. The rule decides which alerts trigger the response. Connecting a tenant alone blocks nothing.
Prerequisites
Section titled “Prerequisites”- Exchange Online, with or without Microsoft Defender for Office 365.
- A Global Administrator, Privileged Role Administrator, or Cloud Application Administrator in Microsoft Entra ID to grant admin consent and assign a role.
- The network enforcement add-on on the Have I Been Squatted organization, and an organization admin to configure it.
What is granted
Section titled “What is granted”Have I Been Squatted uses one multi-tenant Microsoft Entra application for this integration, Have I Been Squatted - Email Response. It is separate from the Microsoft 365 Email Intelligence and Defender for Endpoint applications. Consent grants it:
| Permission | API | Type | Purpose |
|---|---|---|---|
Exchange.ManageAsApp |
Office 365 Exchange Online | Application | Run Exchange Online commands |
User.Read |
Microsoft Graph | Delegated | Sign-in only, to identify the tenant and its initial domain |
Exchange.ManageAsApp lets the application call Exchange Online, but Exchange
only runs a command that a role assigned to the application allows. The
application has no read access to mail, mailboxes, or other Microsoft 365 data.
The customer supplies no credential. Have I Been Squatted authenticates with its own application secret and requests a short-lived token for the tenant on each delivery.
Connect
Section titled “Connect”- In the app, open Connectors > Microsoft 365 Quarantine.
- Select Connect tenant and sign in as an administrator who can grant admin consent.
- Review the requested permissions and accept them on behalf of the organization.
- Assign the application a role, as described in the next section.
- On the settings page, optionally add Protected domains.
- Select Test connection.
The tenant is taken from the verified identity token of the administrator who signed in, never from the address bar. A Microsoft tenant can be connected to only one Have I Been Squatted organization.
Exchange organization
Section titled “Exchange organization”Exchange Online routes each request through the tenant’s initial domain, for
example contoso.onmicrosoft.com. Have I Been Squatted reads it from Microsoft
Graph during sign-in, using the User.Read permission. If it can’t, enter it
on the settings page; it is listed in the Microsoft 365 admin center under
Settings > Domains.
Assign a role
Section titled “Assign a role”Exchange Online requires the application to hold a role that can manage the Tenant Allow/Block List. In the Microsoft Entra admin center, open Roles & admins, select Security Administrator, choose Add assignments, and select Have I Been Squatted - Email Response.
Security Administrator is the narrowest Microsoft Entra role supported for Exchange Online application access that can manage the Tenant Allow/Block List. Role assignments can take a few minutes to reach Exchange Online.
Connection check
Section titled “Connection check”The check requests the same token delivery uses and reads the Tenant Allow/Block List through Exchange Online. Blocking stays off until a check passes. Changing the Exchange organization turns blocking off until the next check passes.
The check reads the list and never changes it, so it can’t prove that the role allows writing. A read-only role such as Security Reader passes the check, and deliveries then fail with a permission error.
| Result | Meaning |
|---|---|
| Consent missing | Microsoft has not granted admin consent for the tenant yet, or the application was removed. Test again after a few minutes, then reconnect if it persists. |
| Authentication | Exchange Online did not accept the application’s token. Reconnect with an administrator who can grant admin consent. |
| Role missing | The application has no role that manages the Tenant Allow/Block List. Assign Security Administrator as described above, then test again. |
| Organization not found | Exchange Online did not find the organization. Check that it is the tenant’s initial .onmicrosoft.com domain and that the tenant has Exchange Online. |
| Unreachable | Microsoft timed out, throttled the request, or returned a server error. Test again later. |
| Configuration | The Have I Been Squatted application credential was rejected. This is a platform problem; contact support. |
A failed check pauses blocking until a later check passes. Consent and authentication failures mark the connection as needing reauthorization.
Protected domains
Section titled “Protected domains”Protected domains are optional. Have I Been Squatted never blocks a protected domain or any of its subdomains, whatever a rule cites. Rules already skip lookup results tagged owned, ignored, or false positive, unless the result also carries another tag such as malicious. Use this list for partners and other domains your users exchange mail with. Protected domains apply to new deliveries as soon as they are saved.
Add the response to a rule
Section titled “Add the response to a rule”- Create or edit a rule and open the Response tab.
- Select Add action > Quarantine in Microsoft 365.
- Select the Microsoft 365 destination.
- Save the rule.
The destination is listed only after a connection check has passed. The response needs at least one domain condition in the rule, because only cited lookalike domain records produce blocks.
What is sent
Section titled “What is sent”For each active rule alert that cites lookalike domain records, Have I Been Squatted handles each distinct cited domain, up to 10 per alert:
| Existing entry for the domain | Action |
|---|---|
| None | Create a sender block for 30 days |
| An allow entry | Leave it; nothing is blocked |
| A block entry the tenant created | Leave it unchanged |
| A block entry from Have I Been Squatted, 15+ days left | Leave it unchanged |
| A block entry from Have I Been Squatted, under 15 days | Renew it for 30 days |
| A block entry from Have I Been Squatted set never to expire | Leave it unchanged |
Entries from Have I Been Squatted carry the note
Have I Been Squatted rule <rule ID> alert <alert ID>, which is how they are
recognized. Entries written by the retired Email Intelligence Watchdog count as well.
- Only domains from cited domain (lookalike permutation) records are sent.
- The monitored domain, its subdomains, and protected domains are never blocked.
- A block covers exactly the cited domain. A block on
examp1e.comdoesn’t covermail.examp1e.com; a cited subdomain gets its own entry. - No email content, addresses, or other alert data is sent.
If Exchange refuses one domain, the others are still processed. If Microsoft times out, returns a server error, or rejects the token or role, the remaining domains are not processed and the delivery is not retried.
What is recorded
Section titled “What is recorded”Have I Been Squatted stores the connected tenant ID, the consent time, the Exchange organization, the protected domains, and the time and outcome of the last connection check. For each alert and response, it records the delivery status, the domains it blocked, renewed, or left alone and why, the expiry, and, when a delivery fails, a short error code. Access tokens and Microsoft response bodies are not stored.
Disable and disconnect
Section titled “Disable and disconnect”Disable stops new blocks and keeps the connection, its settings, and rule responses. A passing connection test turns blocking back on.
Disconnect removes the connection, its settings, and the Quarantine in Microsoft 365 response from every rule. The tenant can then be connected to another organization.
Neither action removes entries already in the Tenant Allow/Block List. They stay until they expire, within 30 days, or until an administrator removes them in the Microsoft Defender portal.
Remove access in Microsoft Entra
Section titled “Remove access in Microsoft Entra”Disconnecting does not revoke the consent or the role. To remove the application’s access, remove its Security Administrator assignment and delete Have I Been Squatted - Email Response under Enterprise applications in the Microsoft Entra admin center. Deliveries and connection checks then fail with missing consent.
Limits
Section titled “Limits”- The Tenant Allow/Block List holds at most 500 sender block entries without Defender for Office 365, 1,000 with Plan 1, and 10,000 with Plan 2. Blocks from Have I Been Squatted count toward that limit, together with the tenant’s own entries.
- An entry takes up to five minutes to take effect.
- The integration uses the Microsoft global cloud. Sovereign clouds such as GCC High and DoD are not supported.