You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-office-365/submissions-user-reported-messages-custom-mailbox.md
+28-1Lines changed: 28 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,7 +16,7 @@ ms.collection:
16
16
ms.custom:
17
17
description: "Admins can configure where user reported messages go for analysis: to an internal reporting mailbox, to Microsoft, or both. Other settings complete the reporting experience for users when they report good messages, spam, or phishing messages from Outlook."
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -91,6 +91,7 @@ On the **User reported settings** page, the available settings for reporting mes
91
91
For details, see the [Options for Microsoft reporting tools](#options-for-microsoft-reporting-tools) section in this article.
92
92
93
93
- Use a third-party, non-Microsoft add-in to report email messages.
94
+
- Decide whether to customize the feedback email that's sent to users after an admin reviews and marks the message on the **User submissions** tab on the **Submissions** page.
94
95
- Decide whether users can report email messages from quarantine as they release quarantined messages.
95
96
96
97
For details, see the [Options for third-party reporting tools](#options-for-third-party-reporting-tools) section in this article.
@@ -207,6 +208,32 @@ When **Monitor reported messages in Outlook** is selected and you also select **
207
208
208
209
Messages can appear on the **User reported settings** tab of the **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user>. The **Result** value for these entries is **Not Submitted to Microsoft**. The message formatting requirements are described in the next section.
209
210
211
+
-**Email notifications** section: These options affect the notification email message that's sent to users when an admin selects :::image type="icon" source="media/m365-cc-scc-mark-and-notify-icon.png" border="false"::: **Mark as and notify** on the **Submissions** page at <https://security.microsoft.com/reportsubmission>. The following options are available:
212
+
213
+
-**Results email** section:
214
+
- Select **Customize results email**. In the **Customize admin review email notifications** flyout that opens, configure the following settings on the **Phishing**, **Junk** and **No threats found** tabs:
215
+
-**Email body results text**: Enter the custom text to use. You can use different text for **Phishing**, **Junk** and **No threats found**.
216
+
-**Email footer text**: Enter the custom message footer text to use. The same text is used for **Phishing**, **Junk** and **No threats found**.
217
+
218
+
When you're finished in the **Customize admin review email notifications** flyout, select **Confirm** to return to the **User reported settings** page.
219
+
220
+
-**Automatically email users the results of the investigation**: This feature is available only in Defender for Office 365 Plan 2 organizations with [automated investigation and response (AIR)](air-about.md).
221
+
222
+
> [!NOTE]
223
+
> This feature is currently in Private Preview, isn't available in all organizations, and is subject to change.
224
+
225
+
If a user reports a message as phishing, an investigation in AIR is automatically created. The following options send notification email to the user who reported the message based on the results from AIR (select one or more options):
226
+
227
+
-**Phishing or malware**: An email notification is sent to the user who reported the message as phishing when AIR identifies the threat as phishing, high confidence phishing, or malware.
228
+
-**Spam**: An email notification is sent to the user who reported the message as phishing when AIR identifies the threat as spam.
229
+
-**No threats found**: An email notification is sent to the user who reported the message as phishing when AIR identifies no threat.
230
+
231
+
For more information, see [Automatic user notifications for user reported phishing results in AIR](air-user-automatic-feedback-response.md).
232
+
233
+
-**Customize sender and branding** section:
234
+
-**Specify a Microsoft 365 mailbox to use ads the From address of email notifications**: Select this option and enter the sender's email address in the box that appears. If you don't select this option, the default sender is `[email protected]`.
235
+
-**Replace the Microsoft logo with my organization's logo across all reporting experiences**: Select this option to replace the default Microsoft logo that's used in notifications. Before you do this step, follow the instructions in [Customize the Microsoft 365 theme for your organization](/microsoft-365/admin/setup/customize-your-organization-theme) to upload your custom logo.
236
+
210
237
-**Report from quarantine** section \>**Allow reporting for quarantined messages**: Verify that this setting is selected to let users report messages from quarantine as they [release quarantined email messages](quarantine-end-user.md#release-quarantined-email). Otherwise, uncheck this setting.
211
238
212
239
When you're finished on the **User reported settings** page, select **Save**.
0 commit comments