Microsoft is giving compliance teams a powerful new enforcement lever: a Purview Data Loss Prevention (DLP) action that physically removes files from SharePoint Online and OneDrive for Business when they violate policy, moving them into a secure quarantine site and replacing them with a configurable text placeholder. General availability is scheduled for July 2026, according to the Microsoft 365 roadmap (ID 557190), and the feature has been rolling out progressively since a preview in March 2026. For organizations handling sensitive data, this marks a shift from simply restricting access to forcibly isolating content—and it will require careful preparation.

The new quarantine action: what it actually does

The File Quarantine action is the most severe enforcement option yet for SharePoint and OneDrive. When a DLP rule fires, Microsoft 365 executes a multi-step sequence: it strips all permissions and sharing links, moves the file to a designated SharePoint quarantine site (preserving the original folder structure for investigators), and replaces it with a tombstone text file containing a custom message. The content owner, site admins, and even service accounts lose access to the relocated file, which can only be re-exposed through a manual review process.

Unlike traditional DLP blocks that restrict access but leave the document in its original location, quarantine treats the storage location itself as compromised. According to Microsoft’s documentation, the move is performed by a system account, and the operation is recorded in DLP alerts, Activity Explorer, and audit logs. The feature is designed for SharePoint and OneDrive files that are newly created or modified after a quarantine-enabled policy is activated; existing, unchanged files are not retroactively swept up.

How quarantine differs from blocking—and why it matters

Blocking stops sharing or access; quarantine removes the asset. That difference has practical consequences. A blocked file might still be visible to some users through inherited permissions, cached links, or synchronization. A quarantined file is physically absent from the original location, which reduces exposure immediately. The trade-off is disruption: co-authoring stops, links break, and automated workflows that reference the file can fail. Quarantine is not a gentle nudge—it’s a containment event.

The tombstone file left behind is a critical communication channel. Administrators configure a central message that replaces the original filename with a .txt version, explaining that the document was moved by an organizational data protection policy and directing the user to the compliance team. A vague message like “File blocked” will generate confusion and support tickets; a well-crafted one can defuse tension and guide users toward legitimate resolution.

What file quarantine means for you

For IT and compliance teams

You gain a tool that can forcibly isolate sensitive data—financial records, trade secrets, personal information, credentials—that appears where it shouldn’t. This is particularly useful when a file contains regulated content in an open project site or an unapproved OneDrive account. However, the power comes with operational overhead: restoration is manual. Microsoft does not currently provide an automated restore button. Investigators must locate the quarantined file, identify its original path, move it back, and reconfigure permissions—original sharing links and version history are not preserved. A mature incident response playbook is essential.

Licensing requires Microsoft 365 E5, and setup privileges are restricted to roles like Compliance Administrator or Security Administrator. You’ll also need a dedicated SharePoint site for the quarantine destination—a repository that will concentrate highly sensitive material and must be hardened accordingly.

For everyday users

If you’re a SharePoint or OneDrive user, your first encounter with quarantine may be a missing document and a mysterious text file in its place. It’s not a deletion or ransomware; it’s a security measure. The file will be reviewed by your compliance team, and you’ll need to provide justification for its restoration. Organizations that are transparent about the process and avoid a blame-first culture will see fewer shadow IT workarounds.

How we got here

DLP for Microsoft 365 has long offered controls like blocking external sharing, policy tips, and alerts. Those work well when a file belongs in its location but needs restrictions. Quarantine addresses cases where the location itself is wrong—when a document should never have been there in the first place. The feature was added to the roadmap on March 12, 2026, and entered preview shortly after. Microsoft updated the rollout status in late July to indicate worldwide availability is imminent.

The move complements existing quarantine capabilities in Endpoint DLP (for local files) and Defender for Cloud Apps, but it’s the first to support cloud-hosted documents in SharePoint and OneDrive directly within a Purview DLP policy.

What to do now: preparation and rollout

If your organization plans to adopt file quarantine, start with a controlled pilot. Microsoft’s processing ceiling is up to 200,000 items per 24 hours, but you don’t want to test that limit accidentally. Begin with these steps:

  1. Verify availability and licensing. Confirm that file quarantine settings appear in the Microsoft Purview portal (under Data Loss Prevention settings) and that your tenant has the necessary E5 entitlements.
  2. Create a dedicated quarantine site. Choose a SharePoint site with no other business content. Apply least-privilege access—only compliance investigators should have access, and even they should operate under tight auditing.
  3. Craft the tombstone message. Make it clear, neutral, and instructive. Example: “This document was moved to a secure review location by a data protection policy. Contact [team email] with the file name and business justification to request review.”
  4. Define a pilot DLP rule. Target a test site and a small OneDrive population. Use precise conditions—combine sensitive information types with sensitivity labels or explicit location scopes. For example, a rule might quarantine files containing financial identifiers plus a “Highly Confidential” label, but only when they appear outside approved finance sites.
  5. Test extensively. Verify behavior with true positives, false positives, renamed files, synchronized content, and files modified after policy activation. Measure alert delivery, restoration time, and the impact on Office desktop applications.
  6. Expand by risk tier. After the pilot, roll out gradually: start with high-confidence secrets or credentials, then expand to regulated identifiers, then broader scenarios only after false-positive rates are understood.
  7. Build a triage workflow. Assign ownership for reviewing alerts, assessing policy matches, and deciding whether to restore, delete, or relocate each file. Document the process so that restoration decisions are consistent and auditable.

The risks and limitations

Quarantine is a scalpel, not a sledgehammer—but in the wrong hands, it can still cause harm. False positives could remove business-critical documents. Original permissions, links, and version histories are lost upon restoration. The quarantine site becomes a high-value target for attackers or insider misuse. And because the same rule won’t re-quarantine a restored file, you need to track exceptions carefully.

Microsoft’s documentation still shows preview-era notes in some places, so expect some UX discrepancies during the rollout. Also, the manual restore process can become a bottleneck if alert volumes spike—plan your investigation capacity accordingly.

What’s next

Once general availability lands in July 2026, watch for Microsoft to refine restoration options and possibly introduce automation hooks for case management. The feature’s long-term value will depend on how well organizations integrate it with existing incident response and insider risk workflows. In the meantime, treat this as an opportunity to tighten data governance: repeated quarantines from a particular site or department may reveal gaps in your information architecture that need fixing.