Skip to content
  • There are no suggestions because the search field is empty.

How to Manage Alert Notifications for Phishing Simulations

Today, many security operations teams have set up email notifications for user reported emails under the "User reported" settings in Microsoft Defender. 

However, when running phishing simulations with these settings, the recipient of these notifications also gets alerted to simulations. This means that security teams can spend time going through reported simulations alongside real alerts.

reported item destinations

To avoid this, the alert notifications should be set at the "Alert" level instead. Here's how to do that.

 

Part 1: Configure user reported settings

  1. Go to Microsoft Defender portal: https://security.microsoft.com
  2. Go to Email & collaboration > Policies & rules > Threat policies > User reported settings
  3. Set the reported item destination to Microsoft only:

    reported message destination

 

Part 2: Configure the alert notification

  1. Go to Microsoft Defender portal: https://security.microsoft.com

  2. Go to Email & collaboration > Policies & rules > Alert policy

  3. Find the default policy named: Email reported by user as malware or phish.

    1. This policy generates an alert when users report messages as phishing using the built-in Report button in Outlook, or the Report Message / Report Phishing add-ins.

    Email reported by user as malware or phish
  4. Open the policy and enable/configure Email notifications.

  5. Add the people or shared mailbox/distribution address that should receive the alert notifications.

    set up recipients

  6. Set or confirm the daily notification limit, then save.

 

Microsoft notes that built-in system alert policies are turned on by default, but you can configure whether email notifications are sent and who receives them.

It can take up to 24 hours after creating or updating an alert policy before the change is active.