{"id":529,"date":"2023-08-12T14:43:43","date_gmt":"2023-08-12T07:43:43","guid":{"rendered":"https:\/\/itadmin.blog\/?p=529"},"modified":"2023-08-12T14:43:43","modified_gmt":"2023-08-12T07:43:43","slug":"gophish-simulation-setup-on-microsoft-365","status":"publish","type":"post","link":"https:\/\/itadmin.blog\/?p=529","title":{"rendered":"GoPhish Simulation setup on Microsoft 365"},"content":{"rendered":"\n<p>How to setup a phishing simulation using gophish and ensure mail is not flagged in Microsoft 365 as spam or phishing so that users will actually receive the phishing test mails.<\/p>\n\n\n\n<p>In the environment setup we have Microsoft 365 in hybrid with an on-premise exchange server. The environment has &#8220;Defender&#8221; setup also that include &#8220;safe links&#8221; and &#8220;safe attachments(only useful on 365 accounts, is ineffective with on-prem exchange accounts).<\/p>\n\n\n\n<p>Additionallly, we have an Astaro\/Sophos UTM appliance acting as an additional mail gateway to filter messages.<\/p>\n\n\n\n<p>First we need to add the IP of our gophish mailing server to &#8220;Enhanced Filtering Connectors&#8221; list so it is recognized as phishing.<\/p>\n\n\n\n<p>Head to Micrsosoft 365 Admin center > Security > Email &amp; Collaboration > Policies &amp; Rules > Threat Policies > Advanced Delivery > Phishing Simulation<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"678\" src=\"https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image-1024x678.png\" alt=\"\" class=\"wp-image-532\" srcset=\"https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image-1024x678.png 1024w, https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image-300x199.png 300w, https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image-768x509.png 768w, https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image.png 1403w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Click on EDIT (not ADD)<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"519\" height=\"794\" src=\"https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image-1.png\" alt=\"\" class=\"wp-image-533\" srcset=\"https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image-1.png 519w, https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image-1-196x300.png 196w\" sizes=\"auto, (max-width: 519px) 100vw, 519px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"497\" height=\"858\" src=\"https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image-2.png\" alt=\"\" class=\"wp-image-534\" srcset=\"https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image-2.png 497w, https:\/\/itadmin.blog\/wp-content\/uploads\/2023\/08\/image-2-174x300.png 174w\" sizes=\"auto, (max-width: 497px) 100vw, 497px\" \/><\/figure>\n\n\n\n<p>Then add all the appropriate info to the domains, IPs &amp; URLs<\/p>\n\n\n\n<p>Next&#8230; Safe Links &#8211; adding an &#8220;allowed link&#8221; <\/p>\n\n\n\n<p>Reference from MS Site : <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/tenant-allow-block-list-about?view=o365-worldwide#allow-entries-in-the-tenant-allowblock-list\">https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/tenant-allow-block-list-about?view=o365-worldwide#allow-entries-in-the-tenant-allowblock-list<\/a><\/p>\n\n\n\n<p>UPDATE : If you want to do this, you need to submit your wildcard link to Microsoft.<\/p>\n\n\n\n<p>GENERAL RULE : <br>To avoid browsers from flagging your domain links (not safelinks but chrome or firefox&#8230;) then <strong><span style=\"text-decoration: underline;\">do not send more than 250-300 mails per week<\/span><\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How to setup a phishing simulation using gophish and ensure mail is not flagged in Microsoft 365 as spam or phishing so that users will actually receive the phishing test mails. In the environment setup we have Microsoft 365 in hybrid with an on-premise exchange server. The environment has &#8220;Defender&#8221; setup also that include &#8220;safe&hellip;&nbsp;<a href=\"https:\/\/itadmin.blog\/?p=529\" class=\"\" rel=\"bookmark\">Read More &raquo;<span class=\"screen-reader-text\">GoPhish Simulation setup on Microsoft 365<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_themeisle_gutenberg_block_has_review":false,"_ti_tpc_template_sync":false,"_ti_tpc_template_id":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-529","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/itadmin.blog\/index.php?rest_route=\/wp\/v2\/posts\/529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itadmin.blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itadmin.blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itadmin.blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/itadmin.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=529"}],"version-history":[{"count":2,"href":"https:\/\/itadmin.blog\/index.php?rest_route=\/wp\/v2\/posts\/529\/revisions"}],"predecessor-version":[{"id":535,"href":"https:\/\/itadmin.blog\/index.php?rest_route=\/wp\/v2\/posts\/529\/revisions\/535"}],"wp:attachment":[{"href":"https:\/\/itadmin.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itadmin.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itadmin.blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}