Sophos Email: set up Microsoft 365 quarantine
M365 Quarantine integrates the quarantine maintained by Microsoft 365 into Sophos Email. Administrators gain a unified view in Sophos Fusion (formerly Sophos Central), but Microsoft remains the owner of the native quarantine and its states. A release or deletion in Sophos Fusion is therefore a request to Microsoft 365 and is complete only after processing has been confirmed.
This runbook covers the connection, consent, synchronization, and acceptance test for a Gateway or M365 Mailflow domain that already exists in Sophos Email. General handling of other Sophos quarantine types is outside this setup.
Prepare prerequisites and the change
Before the maintenance window, you need:
- an active Sophos Email environment with the affected domain under Gateway Domains or M365 Mailflow Domains;
- access to Sophos Fusion and a Microsoft 365 administrator account authorized to grant the requested consent;
- domains that match exactly in Sophos Email and Microsoft 365;
- a browser that allows Microsoft pop-ups during setup;
- a controlled recipient and a test message that Microsoft 365 quarantines.
Record the tenant, domain, domain type, consent account, current switch or connection state, maintenance window, and rollback owner. Don’t put credentials or consent tokens in the ticket. Don’t disable existing post-delivery protection: if the integration requires it and it is currently off, Sophos enables it after explicit confirmation.
Prepare the browser and Microsoft sign-in
Sophos opens Microsoft dialogs during setup. The pop-up blocker must therefore allow the relevant Microsoft 365 domains. Sign in to the correct Microsoft tenant with the approved administrator account. End an existing browser session for another tenant first, or isolate it in a separate browser profile.
Pop-ups can also appear later when opening message content or refreshing the M365 list. They connect the browser to Microsoft services and can take time to load. A closed or blocked window must not be treated as granted consent.
Enable M365 Quarantine for the domain
- In Sophos Fusion, open Global Settings, scroll to Email Domain Setup, and select Gateway Domains or M365 Mailflow Domains for the domain type. Alternatively, open My Products > Email Security > Settings and select the appropriate domain type under Email Domain Setup.
- In the domain list, verify the correct domain by tenant, name, and domain type.
- In the M365 Quarantine column, turn on the switch for that domain only.
- If a dialog says post-delivery protection will also be enabled, recheck the impact and domain, then select Proceed.
- Select the approved Microsoft 365 administrator account. Enter its email address and password on first sign-in; with an existing session, the permission dialogs may appear immediately.
- Review every Microsoft dialog completely and accept all requested permissions. These include permissions to manage Exchange as an application and to read or write directory RBAC settings. Partial consent is insufficient for both M365 Quarantine and the dependent post-delivery protection.
- After permissions are granted, select Close. Activation can take a few minutes; don’t close or restart the page prematurely while the Microsoft dialogs are active.
Grant permissions only for the verified tenant. Don’t add another administrator account or a broader domain merely to work around a connection error.
Verify the connection and first synchronization
After a few minutes, confirm in the domain list that M365 Quarantine remains on for the intended domain. Then open My Products > Email Security > Quarantined Messages and select M365 quarantine. The tab must display Microsoft 365 quarantine data for the domain.
The first synchronization retrieves the last seven days. Data then accumulates up to a rolling maximum window of 30 days. Sophos Fusion synchronizes periodically, so recent changes may appear late and older records may temporarily be out of sync. To retrieve Microsoft’s current data on demand, select Refresh and wait for the request to finish. An empty list without a controlled test item doesn’t prove that the connection works.
Test the release and deletion path
Don’t use a production or malicious message for acceptance. Have Microsoft 365 quarantine a clearly named test message for the controlled recipient. Then:
- Under M365 quarantine, search by recipient, sender, subject, and time, and record the message ID and Microsoft reason.
- Open the message details. Confirm a Microsoft pop-up if content is loaded through it.
- Select only an action supported for the test, such as Release. Available actions depend on the state and native Microsoft quarantine category.
- Select Refresh and wait for synchronization.
- In Microsoft 365, confirm the new quarantine state and, for a release, delivery to exactly the intended recipient.
Selecting Release or Delete, a disappearing row, or an unchanged Sophos list isn’t proof of success by itself. Account for filters, delay, and the Microsoft-owned state. For Delete, confirm processing in Microsoft 365; a test deletion doesn’t replace an approved retention process.
Configure user access deliberately
Messages quarantined by Microsoft can appear in the Sophos Central Self Service Portal. If User Settings enables Allow release of M365 quarantine emails for a user, that user sees messages under M365 quarantine and can view and release supported items. The messages also appear in the quarantine summary, where the Reason field identifies their origin as (Microsoft Quarantine).
Enable this release capability only after a separate authorization decision. Messages in Microsoft’s Malware, High Confidence Phish, or Data Loss Prevention (DLP) categories aren’t available in the Self Service Portal for security reasons. An administrator seeing an item in Sophos Fusion therefore doesn’t prove that the user can see or release it.
Repair consent and connection errors
- Failed to establish session: session has timed out. Sign in again with the correct administrator account and complete the consent flow without interruption.
- Failed to create connection: consent for API access wasn’t granted. Run setup again and grant every requested API permission.
- Failed to create connection: consent for data access wasn’t granted. Run setup again and also grant full requested data access.
- Failed to create connection: the domains in Sophos Email don’t match the domains in the Microsoft 365 domain. Compare the domain names and tenant mapping on both sides and correct the mismatch; don’t continue with an unrelated tenant.
- Failed to create connection: (reason not specified). Check pop-ups, the active Microsoft tenant, administrator authorization, and domain mapping, then repeat setup once cleanly. Escalate with the data below if the error persists.
- Missing or empty list: check the domain switch and post-delivery protection, select M365 quarantine rather than a Sophos quarantine list, wait at least a few minutes, and select Refresh. Then test against the known item instead of relying only on the result count.
- Action remains unchanged: inspect the message ID and state in Microsoft 365, reload synchronization, and check whether the action is supported for that Microsoft category and state. Don’t click repeatedly or create a Sophos allow entry as a workaround.
Treat consent repair as a privileged change: confirm the correct tenant, allow browser pop-ups, rerun setup with an authorized account, and accept every dialog completely. Don’t cycle the domain switch without understanding the impact on post-delivery protection and user access.
Complete, roll back, and escalate
Acceptance passes when the switch remains enabled, M365 quarantine loads data from the correct tenant, the test item is matched by message ID, and Microsoft 365 confirms the requested test action and delivery or status. Record the time, tenant, domain, consent account, granted permission classes, synchronization time, message ID, and result in the change, but no message bodies or credentials.
If activation fails before consent succeeds, end the change without broad substitute permissions and retain the documented starting state. If post-delivery protection was newly enabled or user release was changed in the same change, revert it only after impact review and according to the approved backout. Don’t remove an existing protection feature merely because a list is delayed.
For escalation, collect the tenant ID, domain and domain type, UTC time, consent account, browser and pop-up state, exact error text, state of M365 Quarantine and post-delivery protection, time of the last Refresh, and the controlled test message ID. Never include passwords, tokens, or unnecessary message content.