Microsoft/Office 365 Whitelisting
Microsoft/Office 365 Whitelisting
Microsoft 365 has multiple filtering layers. The recommended approach is the Advanced Delivery phishing-simulation override; the layered allow-lists below are a belt-and-braces fallback. Get your current values from Sending Domains & IPs first.
1. Advanced Delivery — phishing simulation override (recommended)
- Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → Advanced delivery.
- Open the Phishing simulation tab → Add.
- Enter your PhishGrid sending domains, sending IPs, and simulation URLs (from Settings → IP & Domains).
- Save. This tells Defender the mail is an authorised simulation and stops it being filtered or detonated.
2. Whitelist by header (strong, optional)
If your PhishGrid account stamps simulation mail with a custom header, add an Exchange mail flow rule: if the message header matches your PhishGrid simulation header → Set SCL to -1 (bypass spam). This survives domain/IP changes.
3. Layered allow-list (fallback)
- Anti-phishing policy → Allowed senders and domains — add your PhishGrid domains.
- Anti-spam inbound policy → Allowed senders/domains — add your PhishGrid domains.
- Exchange Admin Center → Mail flow → Rules → Bypass spam filtering — condition: sender domain is your PhishGrid domain(s); action: Set SCL to -1.
- Connection filtering — add your PhishGrid sending IPs to the allowed IP list.
- Spoof intelligence → Allow — allow your PhishGrid senders if flagged as spoof.
4. Stop URL & attachment scanning breaking results
- Safe Links → Global settings → Do not rewrite the following URLs — add your PhishGrid simulation domains, or rely on the Advanced Delivery entry above.
- Safe Attachments — exclude your PhishGrid senders from detonation (only if simulations use attachments).
5. Verify
Send a 5–10 user test; confirm inbox delivery and that clicks record correctly. If quarantined, check the Quarantine portal and confirm the Advanced Delivery entry.
Console menus and labels vary by product version and edition — use these as a guide and confirm against your gateway's admin documentation. Always whitelist the current values from Sending Domains & IPs, and send a 5–10 user test campaign before launching organisation-wide.