You need to configure your organization to automatically quarantine all phishing email messages.
To complete this task, sign in to the Microsoft 365 portal.
Answer: You need to edit the Anti-Phishing policy.
– Go to the Office 365 Security & Compliance admin center.
– Navigate to Threat Management > Policy > ATP Anti-Phishing.
– Click on Default Policy.
– In the Impersonation section, click Edit.
– Go to the Actions section.
– In the If email is sent by an impersonated user: box, select Quarantine the message from the drop-down list.
– In the If email is sent by an impersonated domain: box, select Quarantine the message from the drop-down list.
– Click Save to save the changes.
– Click Close to close the anti-phishing policy window.