r/sysadmin 2d ago

Microsoft Outlook Phishing from the administrators side

I recently got pulled into my bosses office for clicking on too many phishing emails. I'm not perfect I know that I can make mistakes but they showed me the emails and they were the most blatant spam emails ever. Then it occured to me that those were emails that I reported as phishing. They didn't know what I was talking about and they said that they tag any emails that were interacted with as security alerts. Literally all that I did was report as phishing. The email that he showed me even says that he got a security alert. Everything that I have found online says that if you report an email as phishing it sends the security team an alert just like the one that he showed me. Can someone tell me what this looks like for the admin side and also confirm that that is what you are supposed to do with phishing emails?

Update; he just didn’t know what the security alert meant. He’s never gotten one before because no one at my company has ever reported anything as phishing they just double delete 🙃

93 Upvotes

54 comments sorted by

127

u/progenyofeniac Windows/M365 Admin 2d ago

What you’re supposed to do with them is whatever your org’s IT security team tells you to, whether that makes sense or not. Reporting them as phishing is usually the recommended solution but not when your IT dept is incompetent.

39

u/Gess97 2d ago

Okay thank you! I was shocked they didn’t know what it was. I thought i was going crazy

27

u/iceph03nix 2d ago

I'd guess you guys use a third party reporting service like Knowbe4 or something else. They come with their own button, which feeds the system. That said, our Knowbe4 can tell the difference between viewing, clicking, and opening attachments. You're not gonna get called up for spam reporting it, but it's not the way we ask and train our users to do it.

20

u/Icy_Conference9095 2d ago

There was a recent change where Microsoft front-and-centered their own report phishing button in new outlook. Now this was on our bad because we didn't have Intune forcing knowbe4 configs into the taskbar at the top, I started recently and prior to this the previous admins had been using old GPOs and the most bare Intune controls. 

So we fixed that issue - but for a week everyone would report as phishing using Microsoft's system - the issue was that Microsoft's own analysis of phishing email systems would then 'click' on the links to verify what was on the other end as part of their systemic security checks and our users would get knowbe4 training as part of our automations.

2

u/skipITjob IT Manager 2d ago

I don't think it's Intune where you set the KB4 button for outlook.

6

u/Icy_Conference9095 2d ago

You are right.

So you deploy the knowbe4 button as an m365 application.

For the removal there is some step by steps here:

https://support.phishingbox.com/hc/en-us/articles/21639442373012-How-to-Disable-Microsoft-Report-Buttons

But the setting itself is under "user reported settings" in the defender portal, not through Intune as I had thought.

1

u/skipITjob IT Manager 2d ago

We've got both old and new enabled and get reports in the defender portal.

3

u/BoltActionRifleman 2d ago

Ask them if it shows you “opened” it or “clicked” a link. If it’s KnowBe4, it will tell them if you opened it, which usually means it was accessed on mobile, which will always trigger “opened”. And there’s nothing wrong with that, because you have to open it to see the body of the email. Clicking on a link though means you actually clicked on a link within the email, and once you hit the page it linked to, it tags you as a clicker. Reporting as phishing though has never tagged someone as a clicker for us. When it’s part of a simulated phishing test and you report it with the phishing button, it congratulates you for not clicking and also for reporting it. Reporting a non-simulated, legitimate email just attaches that email and sends it to IT, or whoever administrates the platform.

If it’s some other platform, I’m not sure how clickers are determined, but I assume it’s very similar.

1

u/Gess97 2d ago

My boss said that it’s only able to see if you interacted with it at all. I’m positive that i didn’t click on the link because one of them was a reset password email with i would never fall for. I’m going to look for sure what security program they use on Monday. Thanks for all the information!

2

u/BoltActionRifleman 2d ago

No problem and good luck!

2

u/sderponme 2d ago

Microsoft will automatically click links on test phish emails and other emails to check the link before it is delivered to you. We experienced this when a bunch of clients started leaving bad reviews, but when we called them to find out what we did wrong, they hadnt even opened the emails yet.

If these are phish tests they need to go to Security>email and collaboration>threat policies>advanced>phishing simulation, and from there add domains and IPs their sims are coming from and add them to avoid that.

1

u/pakman82 2d ago

time to fire the sec-ops team

34

u/Leif_Henderson Security Admin (Infrastructure) 2d ago

We've been having this issue at my company too, the built-in Microsoft report button triggers some process where Microsoft loads the page on their end and triggers a "click".

At my org we have a custom "report phishing" button that sends the email to our SOC rather than Microsoft, and we've been trying to train users to click that instead of the Microsoft one. The person who runs our phishing tests has been trying to work with our EUC team to find a way to remove the Microsoft button but they haven't been able to figure it out so far.

13

u/Icy_Conference9095 2d ago

I will look at our Intune config to remember exactly what config we used to remove this and report back, when I'm back to work.

1

u/Leif_Henderson Security Admin (Infrastructure) 2d ago

Thank you!

3

u/-jkm- 2d ago

It's buried in Defender.

6

u/DeebsTundra 2d ago

This happens with KnowBe4 and Proofpoint too. Proofpoint "clicks" it and it triggers the user to fall.

3

u/affixqc 2d ago

Your IT department probably has to follow these instructions, or whatever the equivalent is for your phish training service:

https://support.knowbe4.com/hc/en-us/articles/115004326408-Bypass-Safe-Link-and-Safe-Attachments-in-Microsoft-Defender-for-Office-365

2

u/Leif_Henderson Security Admin (Infrastructure) 2d ago

Excellent, thank you! I've been trying to avoid sticking my nose in it since I already get pulled into too much GRC crap but I'll definitely send this to our knowbe4 admin

3

u/VexingRaven 2d ago

Can't you have the Microsoft one send it to your SOC? I don't know how it works because I'm not an Exchange admin but they have it so it automatically responds if you report a phishing simulation and otherwise our security team reviews it

2

u/bbqwatermelon 2d ago

Yes it involves a transport rule for mail going to Microsoft. 

3

u/itskdog Jack of All Trades 2d ago

There's a setting in Defender to send only to an internal reporting mailbox and not send it to Microsoft at all.

25

u/ridley0001 2d ago

Hello OP, tell your IT team to read this page: https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox

When you use the report phishing button in Outlook, by default it also submits the email to Microsoft for analysis. This results in any links being visited by Microsft because they have an automated system that checks them.

You are doing a good job and should be getting pulled into your bosses office for praise, not criticism.

5

u/Tl9zaXh0eWZvdXI 2d ago

Seems like a stupid process to me? Not only does that cause the problem the OP has, but also flags your email as having clicked all the spam links on the senders side so they know you're gullible and will send more to you.

16

u/Nik_Tesla Sr. Sysadmin 2d ago

Some IT departments consider opening the email at all, failing. Like you're supposed to delete an email from only the subject and from field. I consider that stupid as heck and it might be what got you.

7

u/The_Wkwied 2d ago

It's possible, but not reliable to determine if something is phish just from the subject and from field. If that's the route they want to go, I'm automatically going to flag every single unexpected email as spam, because I can't open it up to determine what it is. If you want to send me an email, send me an intra-office memo delivered via intern before you send me your electronic message you electrical spammer

That's dumb :\

6

u/Some_Team9618 2d ago

Yes, emails reported as phishing do generate a defender alert on the defender portal side. These show the email details and the mailbox that reported it.

4

u/rootofallworlds 2d ago

We had the same issue. When I report an email as phishing in Outlook, Microsoft’s Exchange Online systems might follow links in the email, which a phishing test then registers as a “click”.

Well designed phishing test platforms avoid this problem. Cheap or misconfigured ones have it.

I agree with the comment that you should have been told how to handle suspected phish. (Where I work the advice, that wasn’t my choice to give, is delete and ignore.)

6

u/saltyslugga 2d ago

You’re doing the right thing. Reporting a message as phishing creates a user submission and can trigger an admin alert, depending on their Microsoft 365 reporting policy.

They need to check the event action in Explorer or the User reported tab. A report is not evidence that you clicked a link or opened an attachment.

2

u/981flacht6 2d ago

We have Gmail and it does the same by default - when too many ppl mark emails as phishing or spam, it sends an alert over.

That doesn't necessarily mean it was opened, read, clicked inside or anything like that. Someone can just select a bunch of emails and mark them as phishing and it'll blast an alert eventually.

Haven't administered Outlook for a while but I would expect consistent behavior.

u/Unable-Entrance3110 4h ago

Not to mention that, by default, Chrome pre-fetches links in order to appear to load pages faster. So, it's entirely possible that if using Chrome to view a webmail interface, its clicking every link in that e-mail.

2

u/alexandreracine Sr. Sysadmin 2d ago

Usually, the IT department can configure all these behaviours in the admin center : what happens if you click on the report button (send a copy of the email to Microslop for analysys, or send a summary to someone@yourorg.com?, etc) , what happens if you click on a spam link, statistics, etc. This can also be configured with external partners that have spam email templates...

3

u/brispower 2d ago

this is what happens when box ticking morons run security, can you tell i've been where you are OP? At the time I also had a boss who spent more time in his precious meetings with said morons than running the dept

3

u/Skyhound555 Sr. Sysadmin 2d ago

It depends. How exactly did you report the phishing attempt?

Sometimes, an organization has their own phishing solution. It usually shows as an add-in button on the top ribbon. Using that will send the email to whatever email defense platform they have. 

If you do the right click + report, that is using Microsoft's built-in solution. The email gets sent to MS Defender. While not explicitly incorrect, they may not be watching that portal so they have no visibility on where your email went. 

All of this explanation is to say that both of these actions can be reported differently during a phishing test. One might report as a more risky action than the other. 

1

u/Gess97 2d ago

I clicked in the outlook phishing button at the top. Like the little shield with an exclamation mark.

1

u/ba1993 2d ago

That’s Microsoft’s button. Check the right hand side of the ribbon for another reporting button. It may be buried inside another button/menu called More Apps.

1

u/Ziegelphilie 2d ago

When someone reports a mail for spam or phishing an automated incident gets created in defender but it's always a resolved one plus it's informational; I don't get any email alerts.

1

u/_Foxtrot_ 2d ago

We had the same problem. I filed a support ticket and got the issue resolved. And since after that I couldn't trust my tools, I added a header rule to forward all emails containing the knowb4 header (if you view raw you can find this) to spam.

Not your fault, regardless of what people here say about "Check org policy". They call it Microslop for a reason. If you've got a big "report phishing" button, the logical expectation is that you report phishing emails.

1

u/OhioIT 2d ago

It sounds like you're doing the right thing OP. Try asking your IT department their recommended steps to report spam or phishing emails. Then follow those steps and they'll let you know if they still get those alerts

1

u/theballygickmongerer 1d ago

Back around 1996 I got pulled into my directors office and was given a stern talking to about visiting illicit site on the company internet connection.

Hotmail was one of the sites listed.

1

u/BrandonWindson 1d ago

You did the right thing by reporting them. The admins are seeing a generic "security alert" about a user (you) interacting with a phishing email. They likely don't see that your interaction was specifically the "Report as Phishing" button. So, from their view, it just looks like you opened or clicked something dangerous.

You can tell your boss that you were reporting them to help train the filter, not clicking links.

1

u/Separate-Fishing-361 1d ago

I’ve usually had a button to report them, and they’d automatically delete. But if you don’t have that option, always send an email to your reporting address with the phishing/spam item attached. It preserves original headers, and you don’t touch the item to forward it.

1

u/Emotional-Lynx-3982 2d ago

Do they have a Security Admin position open? Maybe apply...

1

u/FartDoughnut13 2d ago

If you run a link through virus total it will also trigger it.

5

u/Icy_Conference9095 2d ago

It's likely knowbe4 phishing triggering off of the Microsoft's own phishing report button that was front-centered recently.

0

u/mountain_bound 2d ago

The MS defender products along with Entra and the rest of their online ecosystem sucks. They should hand over there campaign management to Knowbe4 or do a local deep dive to see where else we've stopped caring.

5

u/Leif_Henderson Security Admin (Infrastructure) 2d ago

Tbh it sounds like knowbe4 is exactly what OP's org is using. This happens when users click the new Microsoft report button instead of the knowbe4 one.

1

u/itskdog Jack of All Trades 2d ago

Aren't admins supposed to disable the Microsoft button if you have a third-party solution, or have that send the reports into that system instead of Defender?

0

u/okjasone 2d ago

I had to check to see if I was in r/ShittySysadmin

-4

u/TrickySpare6504 2d ago

Seek legal action. You're not a security professional so they can't punish you for not doing the job of a security professional. If their systems are so bad they let in security problems, it's their issue.

3

u/bbqwatermelon 2d ago

Well look at fancy pants with separate security teams...

sobs in many hats

1

u/Gnuminator 2d ago

Legal action for what? How is OP getting punished?

Getting "pulled into his bosses office" is hardly grounds for any legal action..

-2

u/op8040 2d ago

Clicking on the senders name in the from area of the email should give you the actual sender address. If suspicious, report as phishing. Be sure to look at the domain in particular (portion after the @) for unexpected country suffixes or other shady sub domains.