Microsoft 365 Defender: Unblock a Restricted User from Sending Email
How to Remove a User from the Restricted Entities List in Microsoft 365 (E5)
When a user sends too many emails in a short period, Microsoft 365 can automatically restrict that account to protect your tenant from outbound spam and account compromise. In practice, this shows up as the user being placed on the Restricted entities list.
If you are running a Microsoft 365 E5 subscription and need to quickly unblock a user who hit the daily sending limit, this guide walks you through the correct portal and the exact steps to remove them.
What Is the Restricted Entities List?
The Restricted entities list is an email security control used by Microsoft 365 to temporarily limit outbound sending for accounts that appear to be sending spam-like volumes or patterns.
This can happen when:
- A user exceeds the default daily allowed email message limit
- A compromised account starts sending spam
- An automated process sends unusually high volumes
- A mailbox is used by an application incorrectly (misconfigured SMTP or relay use)
Once restricted, the user may see issues like:
- Messages not sending
- NDRs or throttling behavior
- Email delivery delays
Where You Must Go to Remove a User (Important)
To remove a user from the Restricted entities list, you must use:
- Microsoft 365 Defender portal
https://security.microsoft.com
This is the correct portal because Restricted entities is part of email security and anti-abuse controls.
Step-by-Step: Remove a User from Restricted Entities (Portal Method)
1) Open Microsoft 365 Defender
- Go to https://security.microsoft.com
- Sign in with an account that has appropriate permissions (Security Administrator, Global Administrator, or equivalent roles)
2) Navigate to Restricted Entities
- In the left navigation, go to:
Email & collaboration → Review → Restricted entities
Or open directly:
https://security.microsoft.com/restrictedentities
3) Find the Restricted User
- Locate User1 in the list
- Select the user entry
4) Remove the Restriction
- Choose the option to Remove or Unrestrict the user (wording can vary)
- Confirm the action
Within a short period, the user should be able to send mail again.
Alternative Method: Exchange Online PowerShell
If you prefer automation or need bulk action, you can also remove restrictions using Exchange Online PowerShell. In most exam-style questions, however, the focus is on the correct portal for the UI workflow, which is the Microsoft 365 Defender portal.
What to Do Before You Unrestrict the User (Best Practice)
Unrestricting the user fixes the symptom, but you should validate the cause first. A user hitting sending limits can be normal, but it can also signal compromise.
Quick checks:
- Review recent sign-in activity in Entra ID
- Check mailbox forwarding rules
- Look for unusual OAuth app consent or suspicious send patterns
- Confirm whether the user uses bulk mail tools or automated processes
- Run message trace for abnormal outbound activity
If there is any sign of compromise, reset the password, revoke sessions, and enforce MFA before unrestricting.
Why Other Admin Portals Do Not Work for This
Admins often look in the wrong places first. These portals do not manage Restricted entities:
- Exchange admin center: mail flow and mailbox settings, not restricted entity removal
- Microsoft Purview compliance portal: DLP, retention, eDiscovery
- Microsoft 365 admin center: users and licensing
- Microsoft Entra admin center: identity and access controls
Restricted entities is an email security control, which is why the Microsoft 365 Defender portal is the correct place.
Summary
If User1 is on the Restricted entities list because they exceeded daily sending limits:
- Use the Microsoft 365 Defender portal
- Navigate to Email & collaboration → Review → Restricted entities
- Remove the user from the list
This is the supported, real-world method and the correct answer in exam scenarios.
