# Check the restoration scope before undoing a Defender false positive

> How can a quarantined-file restoration affect more than the single file an analyst intended to release?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:10+00:00
- Modified: 2026-09-10T00:52:38+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Playbook
- DSE priority: Information
- Topics: Business Continuity, Cybersecurity
- Reading time: 2 minutes

## What you need to know

How can a quarantined-file restoration affect more than the single file an analyst intended to release?

## Potentially affected

Windows Defender for Endpoint false-positive remediation and quarantined files.

## DSE recommendation

Prefer an explicitly reviewed file-and-device restoration scope over an unexamined bulk undo.

## Article

## Source facts

Defender’s Action center history supports undoing an eligible quarantine action for one file. The interface can also apply an undo to additional instances of that file. An unavailable Undo button indicates that the selected action cannot be reversed there; actions performed through live response cannot be undone. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives).

Microsoft’s command-line CustomEnterpriseBlock restoration example is broader: its warning says it restores all custom-blocked files quarantined on that device during the preceding thirty days. The source also warns that a file quarantined as a potential network threat might not be recoverable. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives).

## Applicability

This brief concerns Windows Defender for Endpoint false-positive remediation and quarantined files. Establish that the file is safe before choosing a restoration method. Restoring an artifact and changing future protection policy are separate decisions.

## DSE recommendation

DSE recommends starting with the completed action’s details and an explicit list of intended file instances and devices. Review any expanded instance selection before executing an undo. Do not translate one approved release into approval for every custom-blocked artifact from the same device. If restoration is unavailable, escalate with the original action and location evidence rather than repeatedly trying broader commands.

## Verification

Check the action outcome and the intended file on each approved device. Compare the actual restoration scope with the approved list and investigate unexpected releases. Preserve the safety determination and action record together. Review any requested exclusion separately, so restoring a wrongly quarantined file does not silently become a permanent reduction in inspection.

## Official references

[Microsoft Learn: Address Defender for Endpoint false positives and negatives](https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives).

## Primary reference

- Name: Address false positives/negatives in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check the restoration scope before undoing a Defender false positive,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-106-check-the-restoration-scope-before-undoing-a-defender-false-positive/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
