Skip to content

Commit 7923a70

Browse files
authored
Update attack-simulation-training-faq.md
Added some details for FAQ around false positives, and for language selection for user facing content.
1 parent 7b9bf52 commit 7923a70

File tree

1 file changed

+20
-3
lines changed

1 file changed

+20
-3
lines changed

defender-office-365/attack-simulation-training-faq.md

Lines changed: 20 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -96,13 +96,24 @@ Either way, it's important to use different payloads to avoid discussion and ide
9696

9797
By default, Outlook is configured to block automatic image downloads in messages from the internet. Although you can [configure Outlook to automatically download images](https://support.microsoft.com/office/15e08854-6808-49b1-9a0a-50b81f2d617a), we don't recommend it due to the security implications (potential automatic download of malicious code or web bugs, also known as web beacons or tracking pixels).
9898

99-
### I see clicks or compromise events from users who insist they didn't click the link in the simulation message
99+
### I see clicks or compromise events from users who insist they didn't click the link in the simulation message OR I am seeing clicks within a few seconds of delivery for many of my users. (False positives)
100100

101-
Third-party filtering services might be to blame. For any non-Microsoft filtering systems that you use, you need to allow or exempt the following items:
101+
These events can occur when there are security devices, or applications that might be inspecting the mail, some of which may include (but not limited to):
102+
103+
- Applications/plugins within outlook that inspect/intercept the message
104+
- Email security applications
105+
- Endpoint security or antivirus software
106+
- SOAR playbooks that auto-triage/auto-respond to reported messages
107+
108+
These kind of applications can look at the website content for the purpose of detecting real phish, and you will need to define exclusions for simulation messages.
109+
110+
Looking through different fields like IP (e.g. EmailLinkClicked_IP) and TimeStamp (e.g. EmailLinkClicked_TimeStamp) may give more details about the event. e.g. if a click occured within a few seconds of delivery, and it is a non-Microsoft IP or not your company/user's IP, then it is likely that a third-party filtering system or another service is intercepting the message.
111+
112+
For any non-Microsoft filtering systems or service that you use, you need to allow or exempt the following items:
102113

103114
- All [Attack simulation training URLs](attack-simulation-training-get-started.md#simulations) and the corresponding domains. Currently, we don't send simulation messages from a static list of IP addresses.
104115
- Any other domains that you use in custom payloads.
105-
116+
106117
### Can I add the External tag or safety tips to simulation messages?
107118

108119
Custom payloads have the option to add the External tag to messages. For more information, see Step 5 in [Create payloads](attack-simulation-training-payloads.md#create-payloads).
@@ -253,6 +264,12 @@ We find that campaigns where the targeted users are identified by Microsoft Entr
253264

254265
Currently, there are 94 built-in trainings on the [Training modules](attack-simulation-training-training-modules.md) page.
255266

267+
### Q: How are languages enabled for experiences like training modules and notifications?
268+
269+
By default, training module uses the browser locale settings to determine the language of the end user. However, once the training has been assigned to a user, then the language selection persists, and future trainings are assigned in that language.
270+
For end user notifications, the service follows the mailbox locale/language, whereas the language for simulation payload is based on the selection made by admin during the creation of simulation.
271+
For landing pages, it uses the Microsoft 365 account language settings, and the settings around preferred and display languages should be set to the desired language. User can also change languages from the dropdown present in the landing pages.
272+
256273
### Q: Are there any limits in targeting users while importing from a CSV or adding users?
257274

258275
A: The limit for importing recipients from a CSV file or adding individual recipients to a simulation is 40,000.

0 commit comments

Comments
 (0)