Microsoft Defender integration
When a user clicks the Report Phishing button, the report lands in the client’s report mailbox and in our system. For clients who run Microsoft Defender, you can go one step further: with the Defender integration connected, we also submit each reported suspicious email directly to the client’s own Microsoft Defender as a phishing threat submission. The message shows up on their Defender Submissions page with Microsoft’s full analysis — the same triage queue their security team already watches — with no mail rules or mailbox plumbing to maintain.
The integration is additive. Reports are always delivered to the report mailbox and any additional recipients regardless of whether Defender is connected, paused, or broken — you never trade away the mailbox copy.
You’ll need
Section titled “You’ll need”- The Report Phishing button deployed for the client. The Defender card lives on the same configuration page, and there’s nothing to submit until users can report.
- A Microsoft 365 administrator for the client’s tenant — you, if you hold admin on their tenant, or their IT contact. Connecting is a one-time admin consent in a Microsoft sign-in window.
Connect Defender for a client
Section titled “Connect Defender for a client”-
Open the client → Tailor → Report Phishing Button. The Microsoft Defender card sits at the top of the configuration page.
-
Click Connect Microsoft Defender. A Microsoft sign-in window opens. Sign in as an administrator of the client’s Microsoft 365 tenant and accept the requested permission. The grant allows the INFIMA Defender application to create threat submissions only — no mailbox or message access.
-
Confirm the connection. Back on the card you’ll see Connected to Microsoft tenant with the client’s Microsoft tenant ID, an Active badge, and a checkbox controlling submissions.
Pause or disconnect
Section titled “Pause or disconnect”- Pause — untick Submit reported phishing messages to Microsoft Defender. The badge flips to Paused, new reports stop flowing to Defender, and the connection is kept so you can resume with one click. Reports keep going to the report mailbox either way.
- Disconnect — removes the connection entirely. Reconnecting later means going through the Microsoft admin consent again, so prefer pausing unless the client is offboarding from Defender.
You’ll know it worked when
Section titled “You’ll know it worked when”- The Microsoft Defender card shows Active and the client’s Microsoft tenant ID.
- After a user reports a genuine suspicious email, it appears in the client’s Microsoft Defender portal under Actions & submissions → Submissions, where Microsoft’s analysis verdict attaches to it.
- The report mailbox still receives its copy of the same report.
Frequently asked
Section titled “Frequently asked”Do our simulated phishing tests end up in the client’s Defender? No. When a user reports one of our tests, we recognize it and handle it in-platform — the user gets their “it was a test” confirmation and the result is recorded. Only genuinely suspicious emails are submitted to Defender, so the client’s submissions queue isn’t cluttered with training noise.
What permissions does the client grant? Only the ability to create threat submissions. We can’t read mailboxes, messages, or anything else in their tenant. The submission contains the reported email itself, which the user’s report already delivered to us.
Does this work with both versions of the add-in? Yes. Version 2 and version 3 of the Report Phishing button both feed the integration — it hooks into the report flow, not a specific add-in.
Should I turn on Defender’s third-party reporting tool setting? In the client’s Microsoft Defender portal, under Settings → Email & collaboration → User reported settings, there’s a separate option to mark that a third-party reporting tool is in use instead of Microsoft’s own. Whether to flip that depends on which version of the Report Phishing button the client has deployed:
- Version 3 — leave it on Microsoft’s default. Don’t mark a third-party tool.
- Version 2 — mark it as third-party. Set the reporting tool to third-party in that same Defender setting.
This is separate from connecting Defender above — that connection submits reports either way. This setting only affects how Defender itself classifies the reporting tool.
The card says “Last submission failed” — what do I do? The message on the card tells you why, and the report mailbox delivery was unaffected. The most common cause is the client’s admin revoking the app’s consent on the Microsoft side — reconnecting (which re-runs the admin consent) clears it. If failures persist with consent intact, contact our support team.
Do I still need the destination-mailbox mail rules that pointed Defender at reports? Not for Defender — the direct integration replaces that workaround and gets you Microsoft’s analysis without any rules. The report mailbox remains the integration point for other tooling (Sentinel, a third-party SOAR, a ticketing system).
Can I connect one Defender tenant for all my clients at once? No — the connection is per client, against that client’s own Microsoft 365 tenant, because submissions must land in their Defender. Repeat the connect step for each client that wants it.
Related
Section titled “Related”- Report Phishing button — deploy the add-in this integration rides on.
- Report Phishing button icon — customize how the button appears in Outlook.
- Tailor to your client — where the Report Phishing button fits in client setup.