The following table captures the impact on security group assignments if the Quarantine Policy was enabled and then you disable it:

Table 1. Security Group Impact of Disabling Quarantine Policy
VM-ID Managed? Security Group Security Group for VM after Quarantine Policy is Disabled
VM1 Yes vm_underlay_sg vm_underlay_sg . When you remove the nsx.network tag from this VM, to take it out from NSX management, this VM also gets the fallback security group assigned to it.
VM2 Yes default

(AWS) or

quarantine

(Microsoft Azure)
The fallback security group you specify when disabling Quarantine Policy. See How to Enable or Disable Quarantine Policy for details.
VM3 No vm_override_sg The fallback security group you specify when disabling Quarantine Policy.
VM4 No default

(AWS) or

quarantine

(Microsoft Azure)
The fallback security group you specify when disabling Quarantine Policy.
Note: Disabling Quarantine Policy is required for undeploying PCG. See Undeploying PCG in the NSX-T Data Center Installation Guide for details.