G DATA Phishing Simulation

To ensure that the links and attachments in our simulated phishing emails are not deleted, Advanced Threat Protection in Defender P1 must be bypassed.

Proceed as follows:

1.

Open the Microsoft 365 Admin Center.

2.

In the left-side menu, click Security.

Screenshot anzeigen
365 Sicherheit

3.

In the left-side menu, click Exchange message trace. Sie gelangen dann in das Exchange Admin Center.

Screenshot anzeigen
365 Nachrichtenablaufverfolgung

4.

In the left-side menu, click Mail flow and then, in the submenu that opens, click Rules.

Screenshot anzeigen
365 Sicherheit

5.

Click Add a rule. In the submenu that opens, select Create a new rule.
A new window opens on the right edge of the screen. Give the rule a name, for example GDATA PhishingSIM BypassLink.

Screenshot anzeigen
365 Regel hinzufügen

6.

Under Apply this rule if…​, select The sender’s IP address is in any of these ranges or exactly matches.

Screenshot anzeigen
365 IP Whitelist setzen

7.

Now enter our IP address here.

You can find the IP addresses and domains we use, which must be allowlisted accordingly in your organization, in Awareness Manager under the Whitelisting tab.
Screenshot anzeigen
365 IP Whitelist setzen

8.

Under Do the following: select Set the message header.

Screenshot anzeigen
365 IP Whitelist setzen

9.

Click Enter text.
A new window opens on the right edge of the screen. Enter the following value there:

X-MS-Exchange-Organization-SkipSafeLinksProcessing

Click Save.

Screenshot anzeigen
365 IP Whitelist setzen

10.

Click Enter text.
A new window opens on the right edge of the screen. Enter the following value there:

1

Click Save.

Screenshot anzeigen
365 IP Whitelist setzen

11.

In the next window, ensure that Rule mode is set to "Enforce" and select a Severity for this rule. Rule overrides are grouped in activity reports by Severity. Severity is only a filter to simplify the use of reports. Severity has no Impact on the priority in which the rule is processed.

  • Not specified

  • Low

  • Medium

  • High

  • Do not monitor: Rule matches are not displayed in rule reports

Screenshot anzeigen
365 Regel hinzufügen

12.

Click Next.

Screenshot anzeigen
365 Regel hinzufügen

13.

In the next window, review the settings again and click Finish.

Screenshot anzeigen
365 Regel hinzufügen

14.

Your rule is then available in your rule list. However, it is still disabled. Click the word Disabled and a new window opens on the right edge of the screen.

Screenshot anzeigen
365 Regel deaktiviert

15.

Set the status slider to Enabled.

Screenshot anzeigen
365 Regel deaktiviert

16.

Repeat steps 5–15 with the following differences:

  • In step five, assign a different name, for example "GDATA PhishingSIM BypassAttachment"

  • In step nine, use the following value:

X-MS-Exchange-Organization-SkipSafeAttachmentProcessing

Afterward, the bypass for links and attachments is configured.