| This article covers how to configure Microsoft's native Outlook "Report" button to work with NINJIO's simulated phishing reporting platform. |
-
Setup shared mailbox
Microsoft requires an internal mailbox as the destination for reported emails. A shared mailbox is recommended for this purpose, as it does not require a license.- Go to Exchange Admin Center, under “Recipients”, select “Mailboxes”
- Click “Add a shared mailbox”
- For “Display name”: We recommend “Report Phish”
- For “Email address”: We recommend “report-phish”. Select your preferred domain.
-
Configure mail routing
A mail flow rule will be created to automatically route simulated phishing emails to the NINJIO reporting platform.- Within Exchange Admin Center, under “Mail flow”, select “Rules”
- Click “Add a rule”, then “Create a new rule”
- For “Name”: We recommend “NINJIO Simulated Phish Forwarder”
- For “Apply this rule if”: Select “The subject or body” and “subject includes any of these words”
-
Enter each of the following, clicking “Add” after each:
[168.245.68.235] [69.72.33.74] [198.244.55.48] client-ip=168.245.68.235 client-ip=69.72.33.74 client-ip=198.244.55.48 - Then click “Save”
- For “Do the following”: Select “Add recipients” and “to the Cc box”
- Enter ”reported-messages@ninjio.com”, select it within the Suggested results, click “Save”, then “Next”
- For “Severity”: Select “Low”
- For “Comments”: We recommend “This is a rule to forward simulated phish to NINJIO when users click the Outlook Report Phish button”
- Click “Next”, then “Finish”, then “Done”
- Still on the Mail flow->Rules page, click into the rule we created (e.g. “NINJIO Simulated Phish Forwarder”)
- For “Enable or disable rule”: Toggle it to “Enabled”
-
Configure Outlook button
The native Outlook Report button will be enabled and deployed to all users.
-
Go to Microsoft Defender - User reported settings
-
Under “Outlook”:
- Ensure “Monitor reported messages in Outlook” is checked
- Ensure “Use the built-in Report button in Outlook” is checked
-
Under “Reported message destinations”:
- Select “Microsoft and my reporting mailbox”
- Add the shared mailbox we created (e.g. “Report Phish”)
-
Under “Outlook”:
- Click “Save”, it may take several hours from this point to propagate to users.
-
Go to Microsoft Defender - User reported settings
Comments
0 comments
Article is closed for comments.