Your organization has a Microsoft 365 tenant with all users hosted in Exchange Online. It's a new tenant and all the defaults are still in place.

You manage email security. Where do suspicious emails go?

Messages that are flagged as high confidence phishing go to the

Message that contain word-filtered content go to

By default emails that contain word-filtered content is considered spam and are directed to the user's junk email folder.

Phishing messages are directed to the junk folder or the quarantine depending on the confidence level. High confidence phishing emails, in other words, emails that Microsoft 365 is confident it is phishing will go to the quarantine while messages that Microsoft 365 is not 100% positive is phishing will go to the junk email folder.

