Phishing Simulation

Microsoft/Office 365 Whitelisting

Microsoft/Office 365 Whitelisting

Microsoft 365 has multiple filtering layers. The recommended approach is the Advanced Delivery phishing-simulation override; the layered allow-lists below are a belt-and-braces fallback. Get your current values from Sending Domains & IPs first.

  1. Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → Advanced delivery.
  2. Open the Phishing simulation tab → Add.
  3. Enter your PhishGrid sending domains, sending IPs, and simulation URLs (from Settings → IP & Domains).
  4. Save. This tells Defender the mail is an authorised simulation and stops it being filtered or detonated.

2. Whitelist by header (strong, optional)

If your PhishGrid account stamps simulation mail with a custom header, add an Exchange mail flow rule: if the message header matches your PhishGrid simulation header → Set SCL to -1 (bypass spam). This survives domain/IP changes.

3. Layered allow-list (fallback)

  • Anti-phishing policy → Allowed senders and domains — add your PhishGrid domains.
  • Anti-spam inbound policy → Allowed senders/domains — add your PhishGrid domains.
  • Exchange Admin Center → Mail flow → Rules → Bypass spam filtering — condition: sender domain is your PhishGrid domain(s); action: Set SCL to -1.
  • Connection filtering — add your PhishGrid sending IPs to the allowed IP list.
  • Spoof intelligence → Allow — allow your PhishGrid senders if flagged as spoof.

4. Stop URL & attachment scanning breaking results

  • Safe Links → Global settings → Do not rewrite the following URLs — add your PhishGrid simulation domains, or rely on the Advanced Delivery entry above.
  • Safe Attachments — exclude your PhishGrid senders from detonation (only if simulations use attachments).

5. Verify

Send a 5–10 user test; confirm inbox delivery and that clicks record correctly. If quarantined, check the Quarantine portal and confirm the Advanced Delivery entry.

Console menus and labels vary by product version and edition — use these as a guide and confirm against your gateway's admin documentation. Always whitelist the current values from Sending Domains & IPs, and send a 5–10 user test campaign before launching organisation-wide.