Restricted entities

Wesley Jones 75 Reputation points
2026-03-09T14:52:41.24+00:00

We have an office email address, which has been shared mail box for many years, i recently converted this into a user account as a 3rd party system we used to send email on our behalf wanted to start charging us a lot more for them to send emails for us, so i linked the account to the 3rd party web site and gave them permissions to send from the account, the only problem now is some times when we do a mass email to like 3 or 400 people.

They all bounce back as the account has be restricted, is the way of adding the account to a list some where so that it does not get restricted for sending spam again in the future?

The place its getting blocked is, https://security.microsoft.com/restrictedentities but there does not seem to be perm ignore option only a unblock option.

Exchange | Other
Exchange | Other

A powerful email and collaboration platform developed by Microsoft, designed to support enterprise-level communication and productivity. Miscellaneous topics that do not fit into specific categories.

0 comments No comments

Answer accepted by question author
Jack-Bu 6,775 Reputation points Microsoft External Staff Moderator
2026-03-09T15:33:33.4133333+00:00

Hello Wesley,

Thank you for posting your question on Microsoft Q&A. when sending mass emails (to 300-400 recipients), the account gets restricted for outbound spam, and you're seeing it on the Restricted entities page.

The Restricted entities page is primarily for reactive unblocking after a restriction occurs, but there's no built-in permanent exemption. Instead, the best approach is to proactively configure a custom outbound spam policy in Microsoft Defender for Office 365. This lets you tweak sending limits and behaviors just for this account, helping it stay under the radar while respecting Exchange Online overall caps, like up to 10,000 recipients a day or 30 messages per minute.

First, head over to the Microsoft Defender portal at https://security.microsoft.com/antispam From there, create a new outbound policy with a clear name like "Mass Email Account Policy." Make sure to apply it specifically to this user by adding their email in the Users, groups, and domains section, so it overrides the defaults without impacting anyone else. Next, adjust limits to match your mass emailing needs (these are per-hour and daily caps; set to 0 to use service defaults):

  • Maximum number of external recipients per hour: 500+ if sending externally.
  • Maximum number of internal recipients per hour: Adjust as needed.
  • Maximum number of messages per hour: 100+ for batches.
  • Daily message limit: 2,000–5,000 based on your volume.

For the Restriction placed on users who reach the message limit, choose No action, alert only to avoid full blocks, instead, it just notifies admins. Or use Restrict until the following day for auto-recovery after 24 hours.

After reviewing everything, set the policy's priority higher than the default, hit create, and give it a test run with a smaller batch to make sure it behaves as expected.

Hope this help.


Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

Was this answer helpful?


1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-03-09T14:52:53.9366667+00:00

    There is no way to permanently exempt a mailbox or connector from being restricted. Being added to Restricted entities is a protection mechanism that triggers when outbound sending limits or spam indicators are hit, and it cannot be disabled or bypassed for specific senders.

    To handle this scenario:

    1. Secure and verify the account is not compromised
      A mailbox that hits outbound limits is treated as a likely compromised account. Before unblocking, follow the compromise response guidance (password reset, sign-in log review, mailbox rule checks, etc.) as described in Responding to a compromised email account in Office 365.
    2. Unblock the account when it is restricted
      As an admin, go to the Restricted entities page in the Microsoft Defender portal and unblock the user. After unblocking, restrictions are usually removed within about an hour so the user can send mail again.
    3. Reduce the chance of future blocks
      While the account cannot be whitelisted from restriction, risk can be reduced by:
      • Ensuring the 3rd‑party system sends within Exchange Online sending limits and any configured outbound spam policy limits.
      • Reviewing and adjusting outbound spam policies if appropriate (for example, limits and thresholds) so they better match the expected volume, while still protecting against abuse.
      • Monitoring for unusual spikes in outbound volume or patterns that resemble spam.

    If the account continues to be used for large bulk sends, consider using a dedicated, properly configured bulk‑mail solution or connector that respects Microsoft 365 limits and best practices, and be prepared to remediate and unblock via Restricted entities whenever protection is triggered.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.