G DATA Phishing Simulation
Microsoft Exchange Online and Microsoft Defender default setup phishing simulation
To ensure that the emails of a phishing simulation campaign are delivered to users’ mailboxes without interruption, and without Defender protection measures identifying these emails as spam and filtering them out, Microsoft provides a simple way to set up a bypass of these protection mechanisms.
| Excluded are complex email routing scenarios in which custom connectors route the email message flow. |
Creating a phishing campaign via the Microsoft Defender GUI
1. |
Open the page Advanced delivery in the Microsoft Defender portal Show screenshot
|
||
2. |
On the Advanced delivery page, select the Phishing simulation tab and click Add. Show screenshot
|
||
3. |
Enter our domains and IPs here and click Add.
Show screenshot
|
||
4. |
Review all details once again and click Close Show screenshot
|
All emails that arrive from one of the specified IPs in combination with one of the sender domains will now be forwarded to the recipient’s mailbox without inspection.
Creating a phishing campaign via Windows PowerShell
1. |
Open Exchange Online PowerShell with administrative rights and connect to your Microsoft account. |
||
2. |
Create the phishing policy with the following command:
|
||
3. |
Create the phishing simulation override rule with the following command:
Replace Domain1,Domain2,…Domain10 with our domains—each separated by a comma.
|
All emails that arrive from one of the specified IPs in combination with one of the sender domains will now be forwarded to the recipient’s mailbox without inspection.