---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Request release email from quarantine

# Request release email from quarantine {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

Use this feature to release the email that is quarantined from the Microsoft Purview compliance portal.

## Antes de Iniciar

By default, the base system provides the Request email release from quarantine response option and MSFT Quarantine Release Response Option Rule to release the email from
quarantine. This default record also has the Quarantine Release Approval Rule configured with it to leverage the approval functionality for this action. For more information, see [Create incident response option rules](https://servicenow-prod.fluidtopics.net/615TgkNEGKK4rjF6xt11pQ "Create the incident response option rules that end user or analyst can use while responding to an incident."), [Configure response option for your DLP incidents](https://servicenow-prod.fluidtopics.net/uUiUW3Y4HH_28bsD~agkyg "Use this feature to configure the type of response that an end user or analyst should perform."), and [Create Approval Rules](https://servicenow-prod.fluidtopics.net/9GDQaPjK_LsrNwiLS3lC~Q "Create approval rules to take approval from various levels of approver users whenever an advanced type of response option is selected.").  
Figura 1. MSFT Quarantine Release Response Option Rule Figura 2. Default MSFT Response Option  
Prerequisites:

1. Exchange Online PowerShell module need to be installed on the MID server. For more information, see [Install and maintain the Exchange Online PowerShell](https://learn.microsoft.com/en-us/powershell/exchange/exchange-online-powershell-v2?view=exchange-ps#install-and-maintain-the-exchange-online-powershell-module).
2. The MID server needs to communicate with the Exchange server, which is also a cloud service. Therefore, the MID server requires continuous internet access.
{#request-email-from-quarantine__ol_wyn_cyj_kfc}  
Nota:  
If you are using this response option then make sure the mid server is up and running with PowerShell capability. If a mid server is not up and running and doesn't have PowerShell capability then the end user will not be able to select Request email release from quarantine action from the DLP Users workspace. For more information, see [Create incident response option rules](https://servicenow-prod.fluidtopics.net/615TgkNEGKK4rjF6xt11pQ "Create the incident response option rules that end user or analyst can use while responding to an incident.") and [Configure response option for your DLP incidents](https://servicenow-prod.fluidtopics.net/uUiUW3Y4HH_28bsD~agkyg "Use this feature to configure the type of response that an end user or analyst should perform.").

* If you want a specific MID server from the list then you have to configure the MID app and make it visible in the list, and then at least one MID server which is configured should be up and running from the selected mid applications and should have the Power Shell capability.
* For you to use the Release from quarantine option, you need API permissions. On the Microsoft API permissions page, verify Office 365 Exchange OnlineExchange.ManageAsApp is listed and contains the following values:
  *
    * Type: Application.
    * Admin consent required: Yes.
    * Status: The current incorrect value is Not granted for \<Organization\> for the Office 365 Exchange Online \> Exchange.ManageAsApp entry and change the status value. For further steps on the API permissions, see [Assign API permissions to the application](https://learn.microsoft.com/en-us/powershell/exchange/app-only-auth-powershell-v2?view=exchange-ps#step-2-assign-api-permissions-to-the-application) on the Microsoft documentation site.  
      Nota:  
      This step is required to connect to Exchange online using Service principle.
    {#request-email-from-quarantine__ul_np4_kkf_vzb}
  {#request-email-from-quarantine__ul_mzj_jkf_vzb}
* You should also need Security Administrator role in Service Principle,
  * Search for Microsoft Entra ID roles and Administrators in Microsoft Azure portal, and add assignment to the registered app (Service Principle) and then follow the procedure explained on the Microsoft Documentation on how to [assign a role](https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-add-role-to-user#assign-a-role).
  {#request-email-from-quarantine__ul_dyf_dlf_vzb}
* This option is applicable only for Microsoft Exchange incidents which have the Policy Action option as ExQuarantine on the incident form view.
{#request-email-from-quarantine__ul_hcp_1p2_qxb}

Role required: End user

The following procedure explains on how to submit this action from the DLP User Workspace.

## Procedimento

1. Navigate to DLPDLP User Workspace.
2. Open any Microsoft Exchange DLP incident.  
   Verify that the incident Policy Action is set to ExQuarantine.
3. Click Respond.
4. Select Request release mail from Quarantine option from the Response drop down list.  
   Figura 3. Submit incident response - Request email release from quarantine option
5. Click Submit.  
   Nota:  
   When an approval rule is configured for this action, the approval flow will be triggered first and after receiving all the approvals, the Request email release from quarantine flow will be triggered and the email will be released from quarantine. The state of the DLP Incident will be updated to Released from Quarantine after successful release.

