Link to home
Create AccountLog in
Outlook

Outlook

--

Questions

--

Followers

Top Experts

Avatar of Dan
Dan🇺🇸

How to configure Microsoft Report Phishing button for Defender simulations

We've recently transitioned from KnowBe4 to Microsoft Defender for our phishing simulations and I'm trying to configure the Report Phishing button in Outlook. With KnowBe4, the Phish Alert button would not send phishing simulations to the internal mailbox. However, Microsoft's Report Phishing button is sending all reported emails, including simulations, to the specified internal mailbox. Is there a way to prevent simulations from cluttering the mailbox so we only see actual phishing attempts?

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of AmitAmit🇮🇳

Try below steps
Sign in to the Microsoft 365 Defender portal.
Select “Threat management” > “Policy” > “Threat policies”.
Click on “Anti-phishing” and then click on “Edit policy”.
Scroll down to “Report messages” and select “Custom email address”.
Enter the email address of the mailbox you want to forward actual phishing attempts to.
Click on “Save”.

Avatar of Jian An LimJian An Lim🇦🇺

very valid question. if it deliver to microsoft, it will reenforce, but not when you deliver to your own mailbox. 



https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training-end-user-notifications?view=o365-worldwide


Avatar of DanDan🇺🇸

ASKER

@Amit - Can you send me screen shots of the pages you're referring to? I don't seem to have the same navigation options.

However, I have already configured an address to send reported messages to by going to Settings>Email & Collaboration>User reported settings. The problem is that it sends user reported simulation emails as well as actual phishing emails. Thus it creates a lot of clutter to sort through to determine what we actually need to look into.

User generated image

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of Jian An LimJian An Lim🇦🇺

thats the problem, because it submit to your reporting mailbox only, hence it did not have the automated capability on the link i provided previously. 


Avatar of DanDan🇺🇸

ASKER

Even when I change the settings to report to Microsoft and my reporting mailbox it still sends simulations to the reporting mailbox.

User generated image
We want to know about actual phishing emails so that we can take action if needed. However, we don't want the mailbox cluttered up with 100 users reporting a simuated phishing email every time we run a simulation.

The KnowBe4 Phish alert button has this ability to only send actual phishing emails to the reporting mailbox. Is this not possible with Microsoft?

ASKER CERTIFIED SOLUTION
Avatar of DanDan🇺🇸

ASKER

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account
Outlook

Outlook

--

Questions

--

Followers

Top Experts

Microsoft Outlook is a personal information manager from Microsoft, available as a part of the Microsoft Office suite. Although often used mainly as an email application, it also includes a calendar, task manager, contact manager, note-taker, journal, and web browser.