Quarantined emails can appear in different locations depending on which system blocked them, and the release option may be greyed out depending on your role and where the email is quarantined. This article explains where to look and what to do in each scenario.
Where to find quarantined emails
Quarantined emails from Check Point (Avanan) appear in two places:
Guardz console — Detection & Response → Issues → Quarantined Emails. This view shows emails that Guardz has not yet closed or marked as remediated.
Check Point (Avanan) portal — accessible via Security Controls → Email Protection → Portal Access. This shows all quarantined emails including those already closed or archived in Guardz.
Important: Microsoft 365 processes email first, then Check Point scans it. If Microsoft 365 marks a message as high-confidence spam, it goes into Microsoft Quarantine, not Check Point quarantine. Check the Microsoft 365 Defender portal if the email does not appear in Guardz or the Check Point portal at all.
Why the release button is greyed out
The release (Restore/Approve) button is greyed out in one of three situations:
Your role in the Check Point portal is read-only. By default, Guardz admins have read-only access to the Check Point portal. To release emails directly from the Check Point console, you need Editor access. To request it, go to Security Controls → Email Protection → Portal Access (at the All Customers scope level) and add your user with the Editor role.
The email is marked as Closed or Remediated in Guardz. Once an email is closed in the Guardz console, it becomes read-only there. You will see it as a historical record only. To release it, you must go to the Check Point portal directly (with Editor access).
End-user self-release is not enabled by policy. If an end user is trying to release a quarantined email from the User Portal, self-release must be enabled by an admin. If the policy does not allow it, the Restore button stays greyed out for the end user regardless of what they do.
How to release an email as an admin
Option 1 — From the Guardz console (if the email is not yet closed):
Go to Detection & Response → Issues → Quarantined Emails
Locate the email
Select it and choose Release or Allow
Option 2 — From the Check Point portal (if the email is closed in Guardz, or you need Editor-level access):
Go to Security Controls → Email Protection → Portal Access (All Customers scope)
Make sure your user has Editor role
Log in to the Check Point portal
Locate the quarantined email
Select Restore to send it back to the recipient's inbox
A restored email will appear in the user's inbox with its original sent date, not as a new message.
How end users can release emails themselves
End users who have received a quarantine notification email can:
Click the link in the quarantine notification email to open the User Portal
Or go directly to https://app.guardz.com/user-portal and sign in with their Microsoft 365 account
Open Quarantined Emails, find the message, and click Restore
Note: End users can only release emails if the policy allows self-release. If the option is greyed out, an admin needs to release it on their behalf.
The email no longer appears in the portal
Quarantined emails are retained for a fixed period. If an email is no longer visible in the portal, its retention window has expired and it can no longer be restored.
If you can still see other emails from the same date but not a specific one, check two things:
Different portal views — the User Portal only shows emails assigned to that specific user. As an admin, also check Detection & Response → Issues → Quarantined Emails, which shows all quarantined messages across all users.
Issue status filter — in the Guardz console, emails that have been closed or archived may be hidden by the default filter. Change the filter to include all issue statuses. The email may appear as 'Archived' or 'Closed' and can still be restored from the Check Point portal if you have Editor access.
Outbound emails quarantined and not visible in Guardz
Outbound emails held for review (for example, emails containing PII detected by the data protection engine) appear in the Check Point portal, not in the Guardz console outbound view. The Outbound tab in the User Portal only appears if self-restore is enabled by an admin. If you make a policy change to allow a previously blocked attachment or pattern, allow up to 24 hours for the change to fully propagate before the emails are delivered.
