G DATA Phishing Simulation
Bypassing Advanced Threat Protection in Defender P1 for links and attachments.
To ensure that the links and attachments in our simulated phishing emails are not deleted, Advanced Threat Protection in Defender P1 must be bypassed.
Proceed as follows:
1. |
Open the Microsoft 365 Admin Center. |
||
2. |
In the left-side menu, click Security. Screenshot anzeigen
|
||
3. |
In the left-side menu, click Exchange message trace. Sie gelangen dann in das Exchange Admin Center. Screenshot anzeigen
|
||
4. |
In the left-side menu, click Mail flow and then, in the submenu that opens, click Rules. Screenshot anzeigen
|
||
5. |
Click Add a rule. In the submenu that opens, select Create a new rule. Screenshot anzeigen
|
||
6. |
Under Apply this rule if…, select The sender’s IP address is in any of these ranges or exactly matches. Screenshot anzeigen
|
||
7. |
Now enter our IP address here.
Screenshot anzeigen
|
||
8. |
Under Do the following: select Set the message header. Screenshot anzeigen
|
||
9. |
Click Enter text.
Click Save. Screenshot anzeigen
|
||
10. |
Click Enter text.
Click Save. Screenshot anzeigen
|
||
11. |
In the next window, ensure that Rule mode is set to "Enforce" and select a Severity for this rule. Rule overrides are grouped in activity reports by Severity. Severity is only a filter to simplify the use of reports. Severity has no Impact on the priority in which the rule is processed.
Screenshot anzeigen
|
||
12. |
Click Next. Screenshot anzeigen
|
||
13. |
In the next window, review the settings again and click Finish. Screenshot anzeigen
|
||
14. |
Your rule is then available in your rule list. However, it is still disabled. Click the word Disabled and a new window opens on the right edge of the screen. Screenshot anzeigen
|
||
15. |
Set the status slider to Enabled. Screenshot anzeigen
|
||
16. |
Repeat steps 5–15 with the following differences:
|
Afterward, the bypass for links and attachments is configured.