Restricted senders
Exchange ▸ Restricted senders lists accounts Microsoft 365 has blocked from sending after outbound spam or unusually high sending activity. Search by sender address or reason, unblock one row, or mark several rows and use Unblock marked. The heading checkbox marks or clears every row currently visible through the search.
A sending restriction can indicate compromise. Reset the password, require MFA, revoke suspicious sessions, and review forwarding and inbox rules before removing the restriction. The confirmation repeats this checklist. Microsoft says restrictions normally clear within one hour, but propagation can take up to 24 hours. See Microsoft's restricted-sender remediation guidance.
CloudSergeant uses Microsoft's Get-BlockedSenderAddress and
Remove-BlockedSenderAddress commands. A successful row disappears immediately;
failures remain marked for retry. The cached list is warmed after sign-in and tenant switches,
appears in Home's workspace summary, and can be re-read with Refresh. In a GDAP
customer tenant it uses the selected partner context with no second sign-in. Reading requires
Global Reader, Security Reader or View-Only Organization Management; unblocking requires
Security Administrator, Global Administrator or Organization Management in the customer.
Quarantine
Exchange ▸ Quarantine lists email held by Microsoft 365 protection for the current tenant. Search locally by subject, sender, recipient or Message-ID, and narrow the list by quarantine reason or release status. The list shows when each message arrived and whether Microsoft reports that the signed-in identity may release or delete it. Its expiration remains available after opening Details.
- Details opens the identity-specific quarantine record with policy, release, recipient, message and available-action metadata. Where Microsoft permits header access, the Overview also shows the sender display name, envelope sender and return path, sent-on-behalf-of identity, sender IP and country, network message ID, campaign ID, and DMARC, DKIM, SPF and composite-authentication results. URLs and attachments have their own read-only sections; URLs remain inert text. The Exchange quarantine response does not always include Defender's per-item threat verdict, so an unavailable verdict is labelled Not reported rather than incorrectly calling it clean. Its Safe preview tab converts message HTML to inert plain text, so links, scripts and remote images cannot run or load. The Message headers tab shows the complete SMTP header returned by Microsoft 365 and can copy it to the clipboard. Header-backed fields are omitted, with an explanation, when Microsoft does not permit the signed-in identity to read that message's headers.
- Release sends one message to all its original recipients after confirmation. A released row stays visible with its new status.
- Delete permanently removes one message from quarantine. It is not delivered and cannot be recovered, so the app uses its destructive confirmation.
- Bulk actions start with the checkbox in each row. The checkbox in the column heading marks or clears every row currently visible through the filters. Release marked and Delete marked show their actionable counts and ask once before running. Successful releases are unmarked, successful deletions disappear, and failures remain marked for retry.
The tenant list is warmed in the background after sign-in and after a tenant switch, is shown in Home's cached-workspace summary, and can be re-read with Refresh. The richer record, preview and headers are still fetched only when you open Details. Subjects, senders, recipients and message content stay in the running desktop application: CloudSergeant does not write them to disk or send them to the CloudSergeant service.
In a selected customer tenant, CloudSergeant uses your current GDAP identity. Your GDAP relationship needs a Defender-capable role: Security Reader or Global Reader for viewing; Security Administrator or Global Administrator for release and deletion. Microsoft Defender can apply additional role configuration in the customer tenant.
The page uses the same selected customer-tenant context as the other GDAP administration pages; it has no separate customer-account sign-in. See Quarantine through GDAP.
The shape they share
Each tool is a numbered wizard with a rail down the left. You can click back to any step you have already completed; clicking forward re-runs the same checks the Next button would, so nothing is skipped by taking the shortcut.
Choosing the mailbox
There are three ways to reach a mailbox, and the wizard checks the choice immediately:
- Your own mailbox. Nothing to verify.
- Another mailbox in the tenant. Pick it from the list — typing filters it, matching anywhere in the name or address rather than only the start. The app then tries to open it. If that fails and you have an Exchange role, it offers to grant you Full Access; a first-time grant can take a few minutes to become effective, so the wizard says so and gives you a Check again button rather than pretending it was refused.
- Sign in as somebody else. A second, session-only sign-in for an account that can already open the mailbox. Those tokens are never written to disk and are dropped on sign-out, a tenant switch, or Start over. This is also the route into a mailbox in a customer tenant — see Delegated administration.
The check is a real attempt to open the folder tree, not a permission lookup. Exchange will report that a permission exists before the mailbox will actually accept it, so checking the permission alone would let you get two steps further and then fail.
The filters
All three tools share the same filter set, and they combine — a message must match all of them:
- From and To — a received-date range.
- Larger than — a size in MB.
- Subject contains and From contains — substring matches.
- Has attachments and Unread only.
Leave them all empty and the selected folders are matched in full.
Calculate, then Summary
The Selection step will not let you continue until Calculate has run. It counts up as it scans and finishes on the number of messages and total size that actually matched. Touch a folder tick or a filter afterwards and the figure is discarded — so the numbers on the Summary step always describe the run you are about to start. The Summary step is read-only for that reason, and Execute asks for confirmation.
Runs happen in their own window
Execute hands the work to a separate window showing progress and, at the end, a per-folder result. The wizard resets, so you can set up the next run immediately, and several runs can be in flight at once. Closing a run's window while it is working offers to cancel it rather than orphaning it, and closing the app warns you while any run is still active.
Throttling is handled for you. Exchange answers a heavy mailbox operation with a "come back later" that can be minutes long; the app waits it out — up to fifteen minutes of total waiting per request — and tells you it is waiting, rather than failing the run.
Cleanup
Mailbox → Action → Selection → Summary. Removes or files away mail that matches your filters.
The Action step offers four choices:
| Action | Where the message ends up | Getting it back |
|---|---|---|
| Move to folder… | A destination folder you pick in the same mailbox. | Nothing is deleted |
| Move to Deleted Items | The user's own Deleted Items folder. | The user restores it in Outlook |
| Hard delete | Recoverable Items ▸ Deletions — "the dumpster". Deleted Items is skipped. | Outlook ▸ Folder ▸ Recover Deleted Items From Server |
| Permanent delete | Recoverable Items ▸ Purges. This is the one that frees mailbox space. | Administrator recovery via eDiscovery only, subject to retention policy |
After the message operations finish, Cleanup removes empty custom folders in the selected scope and continues through any empty custom parent folders. Built-in and hidden mailbox folders are never removed. If even one item remains — including when a message operation fails — that folder and its parent chain stay intact.
Neither the user nor you can restore a purged message through Outlook. If the mailbox is under a retention policy or litigation hold, that policy still applies and the item may be retained regardless — which means "permanent delete" does not always free the space you expect. Check Storage & hold on the mailbox first.
Copy / Move
Source → Destination → Options → Selection → Summary. Takes the messages that match your filters and copies or moves them into another mailbox — or another folder in the same one.
- Source and destination are chosen independently, each with the same three options as above. Both can use their own second sign-in, so this works between two mailboxes you reach with different credentials, including across tenants.
- The destination must be a named mailbox — the wizard tells you at that step rather than failing at execution.
- Picking the destination loads its folder tree, which both verifies your access and prepares the landing-folder picker. Choose the mailbox root or one of its subfolders; you can also create a new child folder without leaving the wizard.
- The source folder structure is always preserved. It is recreated beneath the landing folder you chose. Choosing the mailbox root restores the structure at root; choosing a subfolder places the same intact structure below that folder.
- Copy leaves the source intact. Move removes the messages from the source once they are safely in the destination, then removes empty custom source folders and empty custom parents. Built-in and hidden folders are protected, and any remaining item keeps its folder chain.
Export / Import
Direction → Source → Destination → Options → Selection → Summary. Direction comes first because it decides what the next two steps mean: exporting, the source is a mailbox and the destination a folder on disk; importing, it is the other way round.
The archive format
A .zip of .eml files — one file per message, in
a folder tree mirroring the mailbox — plus a small manifest. Because it is an ordinary zip
of ordinary message files, you can open it, inspect it, and read individual messages in
Outlook without CloudSergeant.
The manifest records which of the folders are Microsoft's built-in ones. Without it, an archive taken from a Danish mailbox would import into an English one by creating a new folder called "Inbox" beside the existing Indbakke. With it, the import puts the mail where it belongs whatever language either mailbox uses.
The export file is named for the mailbox and the moment it was taken, so two exports of the
same mailbox cannot overwrite each other. .pst is not supported
in either direction.
Importing
Pick the archive, and the app reads its contents and shows you the folders it holds with their message counts, so you can tick only the ones you want. Choose the mailbox root or a subfolder as the landing point, or create a new child folder in the wizard. The archive's folder structure is always recreated intact below that landing point. By default the app skips messages that are already in the target folder — so re-running an interrupted import does not duplicate mail.
Imported messages arrive as proper received mail, not as drafts. A message larger than 150 MB is reported and skipped rather than attempted, because Microsoft 365 will not accept it.
If an archive ever contains items that are not email, the app tells you how many it found and does not import them. Calendar entries and contacts are not part of this format.
These tools act only because you chose to run them, using your own signed-in permissions. Hard delete and permanent delete above cannot be undone by CloudSergeant or by IT Ribe once run — check the recoverability of the action you pick, and see Terms — Limitation of liability.
Where the mailbox-content wizards do not work
Cleanup, Copy / Move and Export / Import are disabled for the GDAP identity in a delegated customer tenant. Mailbox content is reachable only as the mailbox's owner or as a Full Access delegate, and a partner administrator has no mailbox in a customer's tenant — no administrative role changes that. The way through is the second sign-in: sign in as a user of that tenant who has access to the mailbox. The full explanation is here.