Features
Report Phishing Button
Provide your users with a button in Outlook to report phishing emails. Users are immediately notified whether the email is part of a simulated phishing campaign when they submit an email.
Potential malicious phishing emails are forwarded to a mailbox of your choice for evaluation.
We recommend configuring a user submission mailbox with third party reporting tools. You can find instructions on how to create one here, provided by Microsoft.
Overview
Requirements
- Office365 account and admin permissions for the target tenant
- Manifest.xml file (provided by INFIMA)
- Report phishing mailbox (optional)
Supported Platforms
- Outlook on Windows (Microsoft 365)
- Outlook 2019 or later on Windows
- Outlook 2016 or later on Mac
- Outlook 2019 or later on Mac
- Outlook on iOS
- Outlook on Android
- Outlook on the web
- Outlook on Mac (Microsoft 365)
Deployment
The Report Phishing Button is deployed as a Microsoft App and requires admin permissions in Office 365. Once deployed, the app is enabled for your entire organization.
- Navigate to https://admin.microsoft.com.
- Navigate to Settings > Integrated Apps.
- Click Upload custom apps.
- Select Upload manifest file (.xml) from device.
- Navigate to and select the provided manifest.xml file.
- Click Next.
- Select which users to deploy the button to, we recommend Entire organization.
- Click Next.
- Click Next to accept permissions request.
- Click Finish deployment.
- Wait for the status to show “Deployed”.
- The report phishing button is now deployed to your organization.
Implementation Note
The button will not immediately appear to users following successful deployment. Microsoft suggests that deployments take up to 24 hours before changes are visible.
Usage
Reporting Workflow
User Experience
We designed the phishing report button according to Microsoft provided best practices meaning the user experience is familiar and intuitive for your users.
- When the user finds a suspected email they wish to report, they select Report Phishing from the mail drop down.
- This will open a panel where the user is prompted to confirm the suspected phishing email.
Once the user selects Report Phishing, they are provided a response depending on if the phishing email was part of a simulated campaign.
- Simulated phishing email response
- Phishing email not part of a simulated campaign response
Reporting Format
Messages reported to your security team follow Microsoft's suggested reporting format. This allows for seamless integration with Microsoft advanced security features and phishing prevention.
The subject line for the email is as follows:
3| Suspected Phishing Email - {user email} - {timestamp}
Uninstalling
Follow these steps to remove the Report Phishing button for your organization.
- Navigate to https://admin.microsoft.com.
- Navigate to Settings > Integrated Apps.
- Find the Report Phishing app listed in the apps panel and select it.
- Locate the Actions header in the panel that opened.
- Select Remove app.
- Check the box, "Yes, I'm sure I want to remove the app and associated data."
- Click Remove.