Overview
This article explains the procedure for administrators to check notification details and respond to quarantined items or compromised accounts when a threat is detected by Cloud Protection.
Notes
- The content of this article is based on the product specifications as of July 2026 and is subject to change without notice.
- Cloud Protection administrator privileges are required to view the actual screens or change settings.
-
For information on how to access the Cloud Protection admin console, please refer to the following article.
[Cloud Protection] How to Access the Admin Console
Procedure
Identifying Threats
When Cloud Protection detects a threat, you can configure notifications to be sent via either or both of the following methods.
- Notification on the [Detections] menu screen of the Cloud Protection admin console
- Email notification to a specified email address
Please refer to the notification to check the details of the detected threat.
For information on how to check the [Detections] menu screen in the Cloud Protection admin console, please refer to the following articles.
- [Cloud Protection] Checking Detected Security Events (Threats)
- [Cloud Protection] Checking Compromised Account Information
Responding to Threats
Responding to Quarantined Items
If a file containing malware attached to an Exchange Online item, or a harmful URL, is detected, you can configure the system in advance to quarantine the relevant item.
If the setting to quarantine items is enabled, the administrator must check the details of the quarantined item and decide whether to delete it or release it to restore it to its original location.
If an item remains quarantined for a certain period of time, it will be automatically deleted.
For the procedure to delete or release quarantined items, please refer to the following article.
[Cloud Protection] Checking/Deleting (Releasing) Quarantined Items
Responding to Compromised Accounts
If a connected Microsoft 365 account matches a leaked ID, Cloud Protection also provides information on the severity of the compromised account and the possibility of the account being misused, based on the type of compromised information.
For example, you can check whether only the account's email address has been leaked, or whether the password has also been leaked.
Based on this compromise information, please take measures such as changing the account password or suspending the account.
Measures for compromised accounts cannot be performed within Cloud Protection. Please take the necessary action in the Microsoft 365 admin console or the Access Control admin console as needed.
[Cloud Protection] Checking Compromised Account Information
Translation Disclaimer
This article has been automatically translated from the original Japanese version for your convenience.
While we strive to ensure accuracy, we cannot guarantee its reliability or completeness.
In the event of any discrepancies or questions regarding the content, the official Japanese version shall prevail.