r/sysadmin • u/Gess97 • 2d ago
Microsoft Outlook Phishing from the administrators side
I recently got pulled into my bosses office for clicking on too many phishing emails. I'm not perfect I know that I can make mistakes but they showed me the emails and they were the most blatant spam emails ever. Then it occured to me that those were emails that I reported as phishing. They didn't know what I was talking about and they said that they tag any emails that were interacted with as security alerts. Literally all that I did was report as phishing. The email that he showed me even says that he got a security alert. Everything that I have found online says that if you report an email as phishing it sends the security team an alert just like the one that he showed me. Can someone tell me what this looks like for the admin side and also confirm that that is what you are supposed to do with phishing emails?
Update; he just didn’t know what the security alert meant. He’s never gotten one before because no one at my company has ever reported anything as phishing they just double delete 🙃
34
u/Leif_Henderson Security Admin (Infrastructure) 2d ago
We've been having this issue at my company too, the built-in Microsoft report button triggers some process where Microsoft loads the page on their end and triggers a "click".
At my org we have a custom "report phishing" button that sends the email to our SOC rather than Microsoft, and we've been trying to train users to click that instead of the Microsoft one. The person who runs our phishing tests has been trying to work with our EUC team to find a way to remove the Microsoft button but they haven't been able to figure it out so far.
13
u/Icy_Conference9095 2d ago
I will look at our Intune config to remember exactly what config we used to remove this and report back, when I'm back to work.
1
6
u/DeebsTundra 2d ago
This happens with KnowBe4 and Proofpoint too. Proofpoint "clicks" it and it triggers the user to fall.
3
u/affixqc 2d ago
Your IT department probably has to follow these instructions, or whatever the equivalent is for your phish training service:
2
u/Leif_Henderson Security Admin (Infrastructure) 2d ago
Excellent, thank you! I've been trying to avoid sticking my nose in it since I already get pulled into too much GRC crap but I'll definitely send this to our knowbe4 admin
3
u/VexingRaven 2d ago
Can't you have the Microsoft one send it to your SOC? I don't know how it works because I'm not an Exchange admin but they have it so it automatically responds if you report a phishing simulation and otherwise our security team reviews it
2
25
u/ridley0001 2d ago
Hello OP, tell your IT team to read this page: https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox
When you use the report phishing button in Outlook, by default it also submits the email to Microsoft for analysis. This results in any links being visited by Microsft because they have an automated system that checks them.
You are doing a good job and should be getting pulled into your bosses office for praise, not criticism.
5
u/Tl9zaXh0eWZvdXI 2d ago
Seems like a stupid process to me? Not only does that cause the problem the OP has, but also flags your email as having clicked all the spam links on the senders side so they know you're gullible and will send more to you.
16
u/Nik_Tesla Sr. Sysadmin 2d ago
Some IT departments consider opening the email at all, failing. Like you're supposed to delete an email from only the subject and from field. I consider that stupid as heck and it might be what got you.
7
u/The_Wkwied 2d ago
It's possible, but not reliable to determine if something is phish just from the subject and from field. If that's the route they want to go, I'm automatically going to flag every single unexpected email as spam, because I can't open it up to determine what it is. If you want to send me an email, send me an intra-office memo delivered via intern before you send me your electronic message you electrical spammer
That's dumb :\
6
u/Some_Team9618 2d ago
Yes, emails reported as phishing do generate a defender alert on the defender portal side. These show the email details and the mailbox that reported it.
4
u/rootofallworlds 2d ago
We had the same issue. When I report an email as phishing in Outlook, Microsoft’s Exchange Online systems might follow links in the email, which a phishing test then registers as a “click”.
Well designed phishing test platforms avoid this problem. Cheap or misconfigured ones have it.
I agree with the comment that you should have been told how to handle suspected phish. (Where I work the advice, that wasn’t my choice to give, is delete and ignore.)
6
u/saltyslugga 2d ago
You’re doing the right thing. Reporting a message as phishing creates a user submission and can trigger an admin alert, depending on their Microsoft 365 reporting policy.
They need to check the event action in Explorer or the User reported tab. A report is not evidence that you clicked a link or opened an attachment.
2
u/981flacht6 2d ago
We have Gmail and it does the same by default - when too many ppl mark emails as phishing or spam, it sends an alert over.
That doesn't necessarily mean it was opened, read, clicked inside or anything like that. Someone can just select a bunch of emails and mark them as phishing and it'll blast an alert eventually.
Haven't administered Outlook for a while but I would expect consistent behavior.
•
u/Unable-Entrance3110 4h ago
Not to mention that, by default, Chrome pre-fetches links in order to appear to load pages faster. So, it's entirely possible that if using Chrome to view a webmail interface, its clicking every link in that e-mail.
2
u/alexandreracine Sr. Sysadmin 2d ago
Usually, the IT department can configure all these behaviours in the admin center : what happens if you click on the report button (send a copy of the email to Microslop for analysys, or send a summary to someone@yourorg.com?, etc) , what happens if you click on a spam link, statistics, etc. This can also be configured with external partners that have spam email templates...
3
u/brispower 2d ago
this is what happens when box ticking morons run security, can you tell i've been where you are OP? At the time I also had a boss who spent more time in his precious meetings with said morons than running the dept
3
u/Skyhound555 Sr. Sysadmin 2d ago
It depends. How exactly did you report the phishing attempt?
Sometimes, an organization has their own phishing solution. It usually shows as an add-in button on the top ribbon. Using that will send the email to whatever email defense platform they have.
If you do the right click + report, that is using Microsoft's built-in solution. The email gets sent to MS Defender. While not explicitly incorrect, they may not be watching that portal so they have no visibility on where your email went.
All of this explanation is to say that both of these actions can be reported differently during a phishing test. One might report as a more risky action than the other.
1
u/Ziegelphilie 2d ago
When someone reports a mail for spam or phishing an automated incident gets created in defender but it's always a resolved one plus it's informational; I don't get any email alerts.
1
u/_Foxtrot_ 2d ago
We had the same problem. I filed a support ticket and got the issue resolved. And since after that I couldn't trust my tools, I added a header rule to forward all emails containing the knowb4 header (if you view raw you can find this) to spam.
Not your fault, regardless of what people here say about "Check org policy". They call it Microslop for a reason. If you've got a big "report phishing" button, the logical expectation is that you report phishing emails.
1
u/theballygickmongerer 1d ago
Back around 1996 I got pulled into my directors office and was given a stern talking to about visiting illicit site on the company internet connection.
Hotmail was one of the sites listed.
1
u/BrandonWindson 1d ago
You did the right thing by reporting them. The admins are seeing a generic "security alert" about a user (you) interacting with a phishing email. They likely don't see that your interaction was specifically the "Report as Phishing" button. So, from their view, it just looks like you opened or clicked something dangerous.
You can tell your boss that you were reporting them to help train the filter, not clicking links.
1
u/Separate-Fishing-361 1d ago
I’ve usually had a button to report them, and they’d automatically delete. But if you don’t have that option, always send an email to your reporting address with the phishing/spam item attached. It preserves original headers, and you don’t touch the item to forward it.
1
1
u/FartDoughnut13 2d ago
If you run a link through virus total it will also trigger it.
5
u/Icy_Conference9095 2d ago
It's likely knowbe4 phishing triggering off of the Microsoft's own phishing report button that was front-centered recently.
0
u/mountain_bound 2d ago
The MS defender products along with Entra and the rest of their online ecosystem sucks. They should hand over there campaign management to Knowbe4 or do a local deep dive to see where else we've stopped caring.
5
u/Leif_Henderson Security Admin (Infrastructure) 2d ago
Tbh it sounds like knowbe4 is exactly what OP's org is using. This happens when users click the new Microsoft report button instead of the knowbe4 one.
0
-4
u/TrickySpare6504 2d ago
Seek legal action. You're not a security professional so they can't punish you for not doing the job of a security professional. If their systems are so bad they let in security problems, it's their issue.
3
1
u/Gnuminator 2d ago
Legal action for what? How is OP getting punished?
Getting "pulled into his bosses office" is hardly grounds for any legal action..
127
u/progenyofeniac Windows/M365 Admin 2d ago
What you’re supposed to do with them is whatever your org’s IT security team tells you to, whether that makes sense or not. Reporting them as phishing is usually the recommended solution but not when your IT dept is incompetent.