Windows 10: How to track whom of admins released email from quarantine

Discus and support How to track whom of admins released email from quarantine in AntiVirus, Firewalls and System Security to solve the problem; Hello, I would like to ask you to help me identify how to audit who released the email from quarantine. Case: we have several admins who must have... Discussion in 'AntiVirus, Firewalls and System Security' started by Paco_SK, Nov 4, 2019.

  1. Paco_SK Win User

    How to track whom of admins released email from quarantine


    Hello,

    I would like to ask you to help me identify how to audit who released the email from quarantine.

    Case: we have several admins who must have the ability to release from quarantine, how to track who of them released which email ?


    https://protection.office.com/quarantine


    is it even possible via S&CC or any other way ? Graph API / PowerShell ?


    Thx

    :)
     
    Paco_SK, Nov 4, 2019
    #1
  2. Namslas90 Win User

    admin password?

    You can reset the Admin Password using Windows XP repair; See Here for step by step.

    *Toast :toast:
     
    Namslas90, Nov 4, 2019
    #2
  3. Quarantined Trojan:JS/Flafisi.B

    Trojan:JS/Flafisi.B threat description

    When Windows Defender detects and quarantines a threat you are protected and the quarantined item/file/threat cannot harm your computer anymore. Also: Quarantined items will be removed automatically after some time.

    That being said...

    Why you cannot find/see a Remove possibility, I do not know.

    I'm not a Windows 10/Windows Defender user so I'm not 100 % sure that the below from this site (https://www.microsoft.com/en-us/wdsi/help/antimalware-faq)
    copied/pasted info is correct (later EDIT: info is not correct. See my other replies!):

    On Windows Defender Antivirus for Windows 10 version 1703 and later:

    • Use the Windows search box to find and open the Windows Defender Security Center
    • Navigate to the Virus & threat protection > Scan history.
    • Under Quarantined threats, select See full history
    Once you have reviewed the quarantined items you can:

    • Select Remove all to delete all quarantined software.
    • Select individual files, and then click Remove or
      Restore
      .
    • Select Quarantined items and then View details. You might be asked for an admin password or to confirm your choice.
    ======

    I've seen other posts on a similar threat detection for Flash Player where the user also said he didn't have the Remove option...

    See here:

    ====

    Suggestion to upload the detected file to MS:
    Submit files for malware analysis


    and to also upload it to VirusTotal and/or any other service listed here:
    List of Online File analyzers & services


    In addition you might want to run some scans with one or the other tool mentioned here:

    List of Malware Removal Tools
     
    Jsssssssss, Nov 4, 2019
    #3
  4. How to track whom of admins released email from quarantine

    Windows Defender is missing Restore Button for Quarantined Threats

    It wasn't listed under "Quarantined Threats", but was listed in "See full history" as quarantined. It has been about 2 hours
    and now it is listed under "Quarantined Threats" which now shows the Restore or Delete options. Something must be causing
    a delay in listing the quarantined file under "Quarantined Threats" after they have been found and quarantined by Defender.
     
    Crawdaddy1999, Nov 4, 2019
    #4
Thema:

How to track whom of admins released email from quarantine

Loading...
  1. How to track whom of admins released email from quarantine - Similar Threads - track whom admins

  2. Why can't I release messages from Quarantine?

    in Windows 10 Gaming
    Why can't I release messages from Quarantine?: I'm a school teacher and use Office 365 for email, Teams etc through the Welsh government's Hwb platform. Defender was enabled last summer. In c6 months I've only had 1 genuine spam/phishing email, the other 100+ quarantined messages have been mostly circulars I have signed...
  3. Why can't I release messages from Quarantine?

    in Windows 10 Software and Apps
    Why can't I release messages from Quarantine?: I'm a school teacher and use Office 365 for email, Teams etc through the Welsh government's Hwb platform. Defender was enabled last summer. In c6 months I've only had 1 genuine spam/phishing email, the other 100+ quarantined messages have been mostly circulars I have signed...
  4. Can't Access Quarantined Emails

    in Windows 10 Software and Apps
    Can't Access Quarantined Emails: I frequently get an email that reads: "Microsoft 365 security: You have messages in quarantine. . . Review them within 30 days of the received date by going to the Quarantine page in the Security Center." But when I try to review the message, I am told that my account " is a...
  5. Release from Quarantine

    in AntiVirus, Firewalls and System Security
    Release from Quarantine: I need Microsoft defender to actually release quarantined emails back to my inbox after I tell it to do so, it has quarantined many messages, and has yet to return one as far as I can tell, which hasn’t been a major issue, but now there’s an email with attached material I...
  6. How to remove email from admin

    in Windows 10 Gaming
    How to remove email from admin: Hello,I work in a lab at a university, and I tried to sign into my personal microsoft account on one of the lab computers through excel, so that I could use office. However, now the admin user on the computer uses my personal microsoft account. Thus, anyone can see all my...
  7. How to remove email from admin

    in Windows 10 Software and Apps
    How to remove email from admin: Hello,I work in a lab at a university, and I tried to sign into my personal microsoft account on one of the lab computers through excel, so that I could use office. However, now the admin user on the computer uses my personal microsoft account. Thus, anyone can see all my...
  8. How to remove email from admin

    in Windows 10 Customization
    How to remove email from admin: Hello,I work in a lab at a university, and I tried to sign into my personal microsoft account on one of the lab computers through excel, so that I could use office. However, now the admin user on the computer uses my personal microsoft account. Thus, anyone can see all my...
  9. Is my Admin user account "Shared"? Or Not? With Whom?

    in Windows 10 Network and Sharing
    Is my Admin user account "Shared"? Or Not? With Whom?: When I go to PC\Local Disk (C:)\USERS\Admin\Properties\Sharing tab, in the "Network File and Folder Sharing" box, there is a folder icon named, "admin Shared" (Network Path: \\Dell\Users\admin) Below that is a "SHARE" button. If "admin" is "Shared", why is there a "Share"...
  10. Email Tracking & Email Tracking Blocker‬

    in Windows 10 Customization
    Email Tracking & Email Tracking Blocker‬: Is there any app or something like it what tracks emails sent from windows 10 mail app & blocks other to track you (or even 1 of them)? https://answers.microsoft.com/en-us/windows/forum/all/email-tracking-email-tracking-blocker/c827979e-a5d0-4996-86e2-c88d32de9053