This guide explains how to configure Microsoft 365 to allow our simulated phishing emails to reach your users.
Each section includes the settings you need to enter, along with screenshots where necessary.
Overview
This guide is split up into the following steps:
Section 1: Microsoft Advanced Delivery Phishing Simulation
Section 2: Bypass Junk Email Filtering
Section 3: Bypass ATP Link Processing
Section 5: Troubleshooting & Common Issues
1. Advanced Delivery Phishing Simulation
What does this do?
Advanced Delivery tells Microsoft 365 that emails from our simulation service are legitimate phishing simulations. This helps prevent Microsoft 365 from blocking the emails before they reach your users.
The guide below contains the Domains and IPs to all of our services.
Open Advanced Delivery
- Sign in to Microsoft 365 Admin Centre → All Admin Centres → Security
- From the left-hand menu, select Email & collaboration
- Select Policies & rules → Threat policies.
- Find Advanced delivery and select Phishing simulation.
Add the Domains and IPs
Select Edit (or Add, if no configuration exists).
Enter the following details:
| Service(s) | Sending Domain | Sending IP |
|---|---|---|
| SATT | csatraining.online | 193.115.202.252 |
csatraining1.online | 193.115.202.248 | |
csatraining2.online | 178.17.44.181 | |
csatraining6.online | 193.115.202.254 | |
Your Custom Spoofed Domain(s)* | ||
| QR Phishing | csatraining5.online | 193.115.202.251 |
| GDPR | gdpreducation.co.uk | 193.115.202.246 |
| MPAS | csapolicymanagement.online | 193.115.202.247 |
* If you're unsure what your spoofed domain is, please check with your CSA Agent.
Leave Simulation URLs to allow empty unless otherwise instructed.
Select Save, then Close.
Once complete, your setup should similar to the below, dependant on the services you have
Make sure the domains and IP addresses are entered exactly as shown. A small typo can prevent the configuration from working.
2. Bypassing Junk/Spam Filtering
What does this do?
Microsoft 365 uses spam filtering to decide whether an email should be delivered to a user's inbox or moved to their junk folder.
This rule adds a message header to emails, to ensure Microsoft 365 doesn't send our emails to junk.
Creating the Rule
- Sign in to Microsoft 365 Admin Centre → All Admin Centres → Exchange
- From the left-hand menu, select Mail Flow → Rules.
- Select Add a rule → Create a new rule.
Give the rule the following name:
CSA Junk Bypass
Configure the condition
Under Apply this rule if, select:
The Sender → IP address is in any of these ranges or exactly matches
Add the following IP addresses:
| Service(s) | Sending IP |
|---|---|
| SATT | 193.115.202.252 |
193.115.202.248 | |
178.17.44.181 | |
193.115.202.254 | |
| QR Phishing | 193.115.202.251 |
| GDPR | 193.115.202.246 |
| MPAS | 193.115.202.247 |
Configure the actions
Under Do the following, configure:
Modify the message properties → Set the spam confidence level (SCL) → -1 (Bypass spam filtering) → Save
Click the Plus sign to add another action, then configure:
Modify the message properties → Set a message header → X-MS-Exchange-Organization-BypassClutter to the value true
Next
Set rule settings
Check the following settings:
- Rule Mode: Enforce
- Severity: Not specified
- Stop processing more rules: Disabled
Next
Select Finish.
Enabling the rule and changing the priority
Click the on the CSA Junk Bypass rule in the list
Toggle the rule to enabled
Click Edit Rule Settings and set the priority to 0.
Save
Once complete, your rule should look like the below, dependant on the services you have.
3. Bypassing ATP Link Processing
What does this do?
Microsoft Advanced Threat Protection can rewrite links in emails.
This step tells Microsoft 365 to not rewrite or interfere with the simulation links.
Creating the Rule
Select Add a rule → Create a new rule.
Give the rule the following name:
CSA ATP Bypass
Configure the condition
Under Apply this rule if, select:
The Sender → IP address is in any of these ranges or exactly matches
Add the following IP addresses:
| Service(s) | Sending IP |
|---|---|
| SATT | 193.115.202.252 |
193.115.202.248 | |
178.17.44.181 | |
193.115.202.254 | |
| QR Phishing | 193.115.202.251 |
| GDPR | 193.115.202.246 |
| MPAS | 193.115.202.247 |
Configure the actions
Under Do the following, configure:
Modify the message properties → Set a message header → X-MS-Exchange-Organization-SkipSafeLinksProcessing to the value 1
Next
Set rule settings
Check the following settings:
- Rule Mode: Enforce
- Severity: Not specified
- Stop processing more rules: Enabled
Next
Enabling the rule and changing the priority
Click the on the CSA ATP Bypass rule in the list
Toggle the rule to enabled
Click Edit Rule Settings and set the priority to 0.
Save
Once complete, your rule should look like the below, dependant on the services you have with us.
4. Checklist
Once the above steps are completed, your setup reflect similarly to the below image.
Your setup may vary depending on the services you have.
If you're not sure, you can send some screenshots to your CSA Account Manager who will be happy to help.
5. Troubleshooting & Common Issues
If you're still experiencing some issues with your setup, below are the most common issues we see. If you have addressed the below points and are still experiencing delivery issues, please raise a ticket or email support@cybersecurityawareness.co.uk to make your CSA Agent aware.
Priority of the mail flow rules
CSA Junk Bypass should be Priority 0
CSA ATP Bypass should be Priority 1
The priority of the rules ensures our emails are only impacted by these rules. This reduces the chance of false positives and reduces the risk of our emails interacting with any of your other rules. This will not impact any of your other incoming mail.
Stop Processing More Rules should be enabled on CSA ATP Bypass.
Stop processing more rules means our emails will only interact with our two mail flow rules before being delivered. If stop processing more rules is not enabled, it can cause issues with delivery.
Spoofed Domain missing from Advanced Delivery.
We own all of the domains that we use, including your spoofed domain. Adding this into advanced delivery along with our IPs and Domains stops Microsoft flagging the emails and preventing them from delivering to your users. If you're unsure what yours is, please raise a ticket with your CSA Agent.
3rd Party Mail Security Rerouting Emails.
If you have a 3rd party email filtering system, this can impact what Microsoft believes to be the source IP that our emails have come from.
This can mean that the mail flow rules do not engage with our emails. We would recommend setting up a mail host in order to send directly to your tenancy.
Comments
0 comments
Please sign in to leave a comment.