Integrate PhishNotify with Microsoft Defender

The PhishNotify integrations feature allows Infosec’s PhishNotify add-in to send learner reported emails to Microsoft report submissions for triage and analysis. If you have not yet deployed the PhishNotify add-in follow the instructions found here.

Parts of this article are based on instructions provided by Microsoft found here.

Part 1: Configure Microsoft 365 to ingest emails Reported with PhishNotify

  1. Login to your Microsoft 365 account and go to Settings > Email & collaboration > User Reported
  2. Verify that User Reported emails are enabled and the toggle is in the On position
    User_Reported
  3. Select the option to Use a non-Microsoft add-in button
    non-Microsoft
  4. Key in and select the inbox that will be used to send all reported emails to. This inbox will be used to consume reported emails for threat analysis.
    mailbox

Part 2: Configure PhishNotify to send to Microsoft

  1. In the Infosec IQ admin portal, navigate to PhishNotify & PhishHunter > PhishNotify Setup.
  2. On the " PhishNotify setup and settings" page, under “Select what happens to an email in IQ once a learner reports it,” select one of the following:
    Bypass
    • Save email contents and attachments - reported emails will also be saved in the Infosec IQ quarantine.
    • Bypass Infosec IQ - reported emails will not be saved in Infosec IQ.
  3. Save.
  4. Navigate to PhishNotify Integtrations in the left sidebar.
  5. Select Microsoft Defender from the drop-down.
  6. Enter an email address to which messages will be forwarded. The other fields will be configured according to Microsoft’s requirements.
  7. Save.

Part 3: Test the configuration

Please note when testing that there is a slight delay from the time it takes for the email notifications to be sent and delivered, and for when Microsoft scans the inbox and displays the message.

  1. Report a non PhishSim email with PhishNotify.
  2. Verify the email was delivered successfully to the inbox you configured above.
  3. Go into the Report Submissions section of Microsoft 365 and verify the email appears in this list.