Published: 14 July 2026. Source: Microsoft Learn: DLP file quarantine for SharePoint and OneDrive
A new Microsoft Purview Data Loss Prevention action called File Quarantine has finished rolling out to SharePoint Online and OneDrive for Business. Instead of merely alerting an administrator after sensitive content is exposed, a DLP policy configured with the Quarantine action now removes the offending file from its original location the moment a match is detected, replacing it with a placeholder.
How the quarantine action behaves
When a file matches a policy condition, such as a document containing credit card numbers shared with an external domain, SharePoint moves the file into an admin-controlled quarantine site. A tombstone file takes its place in the original library, carrying a short explanation of why the file was removed and who to contact. The original file's version history and metadata travel with it into quarantine rather than being discarded outright.
What changes for admins day to day
| Before this action | After enabling File Quarantine |
|---|---|
| DLP policy match generates an alert; file stays accessible | DLP policy match removes the file to quarantine; a tombstone replaces it |
| Admin manually restricts access after the alert is reviewed | Access is blocked automatically at the moment of the match |
| End users unaware anything happened until told | End users see the tombstone notice immediately |
The practical effect is that a compliance team spends less time racing to lock down a file before it spreads further, because the quarantine action does that step automatically. Reviewing and releasing a quarantined file (or confirming it should stay isolated) becomes the new manual step, replacing the old race against the clock.
Where this fits alongside broader permission cleanup
File Quarantine only fires when a Purview DLP policy is actively configured to catch a specific type of sensitive content. It says nothing about the dozens of stale unique permissions or shared links that were granted long before any policy existed and were never withdrawn. Those still need a separate audit. ShareMaster's Shared Links & Permissions tool exports every unique permission grant and active shared link for a site so a compliance review isn't relying on DLP alone to catch everything worth catching, and Report Master gives you the underlying permission matrix to check against before any new policy goes live.
Source: Microsoft Learn: DLP file quarantine for SharePoint and OneDrive.
Frequently Asked Questions
What does the DLP File Quarantine action actually do?
It moves a file matching a Purview DLP policy into an admin-controlled quarantine location and replaces it with a tombstone placeholder, so end users can no longer open, download, or share the original.
Can end users see that their file was quarantined?
Yes. The tombstone carries a notice explaining the file was moved due to a policy match and who to contact, though the user cannot open the tombstone itself.
Do I need Microsoft Purview E5 to use file quarantine?
DLP actions for SharePoint and OneDrive require an E5 licence or an equivalent Purview add-on for covered users. Confirm current licensing on Microsoft Learn before assuming availability in your tenant.