Built first and foremost for Microsoft 365.
Quaragate connects to Exchange Online through Microsoft Graph with a least-privilege, app-only identity. It complements Microsoft Defender for Office 365 rather than replacing your mail path.
How it connects
An app-only Microsoft Entra application grant over Microsoft Graph and Exchange Online. No service account password, no MX record change, no connector in the mail path.
Least-privilege scopes
The grant requests only the permissions needed to read mail for analysis and to move malicious messages to quarantine. It is reviewable and revocable in Microsoft Entra.
Setup and prerequisites
A Global Administrator consents once. For partners, tenants are added with delegated (GDAP-style) access, so onboarding many clients does not mean many manual setups.
What is and is not accessed
Quaragate accesses mail in order to analyze and remediate threats. It does not change your mail routing, and it is not a gateway, so it cannot delay or drop the mail your users send and receive. For details on storage, retention, and isolation, see the Trust and security page.
A layer, not a replacement
Keep Microsoft Defender for Office 365 and your existing controls. Quaragate adds the post-delivery layer they lack: continuous re-checking and automatic quarantine of mail that was judged clean at the door but turned out not to be.
Built to fit the rest of your stack
SIEM and SOAR log export, ticketing, PSA and RMM connectors for MSPs, and single sign-on are on the roadmap. Tell us what your team runs on and we will prioritize accordingly.