Skip to content

Commit 8935c2e

Browse files
committed
Merge branch 'main' into deniseb-281044
2 parents 7d496e9 + fa959d2 commit 8935c2e

11 files changed

+38
-33
lines changed

defender-office-365/advanced-delivery-policy-configure.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ Use the _advanced delivery policy_ in EOP to prevent inbound messages _in these
4242
- [AIR and clustering in Defender for Office 365](air-about.md) ignores these messages.
4343
- Specifically for third-party phishing simulations:
4444
- [Admin submission](submissions-admin.md) generates an automatic response saying that the message is part of a phishing simulation campaign and isn't a real threat. Alerts and AIR aren't triggered. The admin submissions experience shows these messages as a simulated threat.
45-
- When a user reports a phishing simulation message using the [built-in Report button in Outlook on the web](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook-on-the-web) or the [Microsoft Report Message or Report Phishing add-ins](submissions-outlook-report-messages.md#use-the-report-message-and-report-phishing-add-ins-in-outlook), the system doesn't generate an alert, investigation, or incident. The links or files aren't detonated, but the message appears on the **User reported** tab of the **Submissions** page.
45+
- When a user reports a phishing simulation message using the [built-in Report button in Outlook](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook) or the [Microsoft Report Message or Report Phishing add-ins](submissions-outlook-report-messages.md#use-the-report-message-and-report-phishing-add-ins-in-outlook), the system doesn't generate an alert, investigation, or incident. The links or files aren't detonated, but the message appears on the **User reported** tab of the **Submissions** page.
4646

4747
Messages that are identified by the advanced delivery policy aren't security threats, so the messages are marked with system overrides. Admin experiences show these messages as **Phishing simulation** or **SecOps mailbox** system overrides. Admins can use these values to filter and analyze messages in the following experiences:
4848

defender-office-365/anti-phishing-protection-tuning.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,7 @@ You can also use the [configuration analyzer](configuration-analyzer-for-securit
8181

8282
- Whenever possible, we recommend that you deliver email for your domain directly to Microsoft 365. In other words, point your Microsoft 365 domain's MX record to Microsoft 365. Exchange Online Protection (EOP) is able to provide the best protection for your cloud users when their mail is delivered directly to Microsoft 365. If you must use a third-party email hygiene system in front of EOP, use Enhanced Filtering for Connectors. For instructions, see [Enhanced Filtering for Connectors in Exchange Online](/Exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/enhanced-filtering-for-connectors).
8383

84-
- Have users use the [built-in Report button in Outlook on the web](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook-on-the-web) or deploy the [Microsoft Report Message or Report Phishing add-ins](submissions-outlook-report-messages.md#use-the-report-message-and-report-phishing-add-ins-in-outlook) in your organization. Configure the [user reported settings](submissions-user-reported-messages-custom-mailbox.md) to send user reported messages to a reporting mailbox, to Microsoft, or both. User reported messages are then available to admins on the **User reported** tab on the **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user>. Admin can report user reported messages or any messages to Microsoft as described in [Use the Submissions page to submit suspected spam, phish, URLs, legitimate email getting blocked, and email attachments to Microsoft](submissions-admin.md). User or admin reporting of false positives or false negatives to Microsoft is important, because it helps train our detection systems.
84+
- Have users use the [built-in Report button in Outlook](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook) or deploy the [Microsoft Report Message or Report Phishing add-ins](submissions-outlook-report-messages.md#use-the-report-message-and-report-phishing-add-ins-in-outlook) in your organization. Configure the [user reported settings](submissions-user-reported-messages-custom-mailbox.md) to send user reported messages to a reporting mailbox, to Microsoft, or both. User reported messages are then available to admins on the **User reported** tab on the **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user>. Admin can report user reported messages or any messages to Microsoft as described in [Use the Submissions page to submit suspected spam, phish, URLs, legitimate email getting blocked, and email attachments to Microsoft](submissions-admin.md). User or admin reporting of false positives or false negatives to Microsoft is important, because it helps train our detection systems.
8585

8686
- Multi factor authentication (MFA) is a good way to prevent compromised accounts. You should strongly consider enabling MFA for all of your users. For a phased approach, start by enabling MFA for your most sensitive users (admins, executives, etc.) before you enable MFA for everyone. For instructions, see [Set up multi-factor authentication](/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication).
8787

defender-office-365/defender-for-office-365-whats-new.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -160,7 +160,7 @@ For more information on what's new with other Microsoft Defender security produc
160160

161161
- The new Microsoft Defender XDR role-based access control (RBAC) model, with support for Microsoft Defender for Office, is now available in public preview. For more information, see [Microsoft Defender XDR role-based access control (RBAC)](/defender-xdr/manage-rbac).
162162

163-
- [Use the built-in Report button in Outlook on the web](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook-on-the-web): Use the built-in Report button in Outlook on the web to report messages as phish, junk, and not junk.
163+
- [Use the built-in Report button in Outlook on the web](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook): Use the built-in Report button in Outlook on the web to report messages as phish, junk, and not junk.
164164

165165
## October 2022
166166

defender-office-365/migrate-to-defender-for-office-365-setup.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,7 @@ You can specify an Exchange Online mailbox to receive messages that users report
7878

7979
You should also confirm that all users in the pilot have a supported way to report messages that received an incorrect verdict from Defender for Office 365. These options include:
8080

81-
- [The built-in Report button in Outlook on the web](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook-on-the-web)
81+
- [The built-in Report button in Outlook](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook)
8282
- [The Report Message and Report Phishing add-ins](submissions-outlook-report-messages.md#use-the-report-message-and-report-phishing-add-ins-in-outlook)
8383
- Supported third party reporting tools as described [here](submissions-user-reported-messages-custom-mailbox.md#message-submission-format-for-third-party-reporting-tools).
8484

defender-office-365/reports-email-security.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1009,7 +1009,7 @@ The **URL protection report** is available only in Microsoft Defender for Office
10091009
> [!IMPORTANT]
10101010
> In order for the **User reported messages** report to work correctly, **audit logging must be turned on** in your Microsoft 365 organization (it's on by default). For more information, see [Turn auditing on or off](/purview/audit-log-enable-disable).
10111011
1012-
The **User reported messages** report shows information about email messages that users have reported as junk, phishing attempts, or good mail by using the [built-in Report button in Outlook on the web](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook-on-the-web) or the [Microsoft Report Message or Report Phishing add-ins](submissions-outlook-report-messages.md#use-the-report-message-and-report-phishing-add-ins-in-outlook).
1012+
The **User reported messages** report shows information about email messages that users have reported as junk, phishing attempts, or good mail by using the [built-in Report button in Outlook](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook) or the [Microsoft Report Message or Report Phishing add-ins](submissions-outlook-report-messages.md#use-the-report-message-and-report-phishing-add-ins-in-outlook).
10131013

10141014
On the **Email & collaboration reports** page at <https://security.microsoft.com/emailandcollabreport>, find **User reported messages**, and then select **View details**. Or, to go directly to the report, use <https://security.microsoft.com/reports/userSubmissionReport>.
10151015

defender-office-365/step-by-step-guides/deploy-and-configure-the-report-message-add-in.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -26,9 +26,9 @@ Depending on whether you're licensed for Defender for Office 365, you also get a
2626

2727
## Choose between which add-in to deploy
2828

29-
- The Report Phishing add-in provides the option to report only phishing messages
30-
- The Report Message add-in provides the option to report junk, not junk (false positive), and phishing messages
31-
- The built-in Report button in Outlook on the web *[Learn More](../submissions-outlook-report-messages.md)*
29+
- The Report Phishing add-in provides the option to report only phishing messages.
30+
- The Report Message add-in provides the option to report junk, not junk (false positive), and phishing messages.
31+
- The built-in Report button in supported versions of Outlook. *[Learn More](../submissions-outlook-report-messages.md)*
3232

3333
## What you need
3434

@@ -55,7 +55,7 @@ Depending on whether you're licensed for Defender for Office 365, you also get a
5555
1. **Login** to the Microsoft Security portal at <https://security.microsoft.com>.
5656
2. On the left nav, select **Settings** and choose **Email & collaboration**.
5757
3. Select **User reported settings**.
58-
4. Ensure **Monitor report messages in outlook** is selected and select **use the built-in report button**.
58+
4. Ensure **Monitor report messages in outlook** is selected and select **Use the built-in Report button**.
5959
5. Under **Send the reported messages to** choose **Microsoft Only** (Recommended).
6060

6161
## Optional steps – configure notifications

defender-office-365/submissions-admin.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -846,8 +846,8 @@ For email messages, admins can see what users are reporting on the **User report
846846

847847
- The [user reported settings](submissions-user-reported-messages-custom-mailbox.md) are turned on.
848848
- **Email messages**: You're using supported methods for users to report messages:
849+
- The [built-in Report button in Outlook](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook).
849850
- The [Microsoft Report Message or Report Phishing add-ins](submissions-users-report-message-add-in-configure.md).
850-
- The [built-in Report button in Outlook on the web](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook-on-the-web).
851851
- [Supported third-party reporting tools](submissions-user-reported-messages-custom-mailbox.md#options-for-third-party-reporting-tools)
852852
- **Teams messages**: [User reporting settings for Teams messages](submissions-teams.md#user-reporting-settings-for-teams-messages) is turned on.
853853

defender-office-365/submissions-outlook-report-messages.md

Lines changed: 19 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -11,10 +11,10 @@ ms.localizationpriority: medium
1111
ms.collection:
1212
- m365-security
1313
- tier1
14-
description: Learn how to report phishing and suspicious emails in Outlook using the built-in Report button or the Report Message and Report Phishing add-ins.
14+
description: Learn how to report phishing and suspicious emails in supported versions of Outlook using the built-in Report button or the Report Message and Report Phishing add-ins.
1515
ms.service: defender-office-365
1616
search.appverid: met150
17-
ms.date: 11/9/2023
17+
ms.date: 08/19/2024
1818
appliesto:
1919
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Exchange Online Protection</a>
2020
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -38,24 +38,30 @@ Admins configure user reported messages to go to a specified reporting mailbox,
3838

3939
[!INCLUDE [MDO Setup guide](../includes/mdo-setup-guide.md)]
4040

41-
## Use the built-in Report button in Outlook on the web
41+
## Use the built-in Report button in Outlook
4242

43-
- The built-in **Report** button is available in Outlook on the web *only* if user reporting is turned on *and* the built-in **Report** button in Outlook (not a non-Microsoft add-in button) are configured in the [user reported settings](submissions-user-reported-messages-custom-mailbox.md) at <https://security.microsoft.com/securitysettings/userSubmission>:
43+
- The built-in **Report** button is available in the following versions of Outlook:
44+
- Outlook for Microsoft 365 and Outlook 2021.
45+
- The new Outlook for Windows.
46+
- Outlook on the web.
4447

45-
If user reporting is turned off and a non-Microsoft add-in button is selected, the **Report** button isn't available in Outlook on the web.
48+
The **Report** button is available in supported versions of Outlook if both of the following conditions are true:
4649

47-
- Currently, the **Report** button in Outlook on the web doesn't honor the before and after notification pop-up options in the user reported settings.
50+
- User reporting is turned on.
51+
- The built-in **Report** button is configured in the [user reported settings](submissions-user-reported-messages-custom-mailbox.md) at <https://security.microsoft.com/securitysettings/userSubmission>.
4852

49-
- Built-in reporting in Outlook on the web supports reporting messages from shared mailboxes or other mailboxes by a delegate.
53+
If user reporting is turned off and a non-Microsoft add-in button is selected, the **Report** button isn't available in supported versions of Outlook.
54+
55+
- The built-in **Report** button in supported versions of Outlook supports reporting messages from shared mailboxes or other mailboxes by a delegate.
5056
- Shared mailboxes require Send As or Send On Behalf permission for the user.
5157
- Other mailboxes require Send As or Send On Behalf permission _and_ Read and Manage permissions for the delegate.
5258

53-
### Use the built-in Report button in Outlook on the web to report junk and phishing messages
59+
### Use the built-in Report button in Outlook to report junk and phishing messages
5460

5561
- Users can report a message as junk from the Inbox or any email folder other than Junk Email folder.
5662
- Users can report a message as phishing from any email folder.
5763

58-
In Outlook on the web, select one or more messages, select **Report**, and then select **Report phishing** or **Report junk** in the dropdown list.
64+
In a supported version of Outlook, select one or more messages, select **Report**, and then select **Report phishing** or **Report junk** in the dropdown list.
5965

6066
> [!div class="mx-imgBorder"]
6167
> :::image type="content" source="media/owa-report-junk-phishing.png" alt-text="The results of selecting the Report button after selecting multiple messages in Outlook on the web." lightbox="media/owa-report-junk-phishing.png":::
@@ -65,9 +71,9 @@ Based on the [User reported settings](submissions-user-reported-messages-custom-
6571
- **Reported as junk**: The messages are moved to the Junk Email folder.
6672
- **Reported as phishing**: The messages are deleted.
6773

68-
### Use the built-in Report button in Outlook on the web to report messages that aren't junk
74+
### Use the built-in Report button in Outlook to report messages that aren't junk
6975

70-
In Outlook on the web, select one or more messages in the Junk Email folder, select **Report**, and then select **Not junk** in the dropdown list.
76+
In a supported version of Outlook, select one or more messages in the Junk Email folder, select **Report**, and then select **Not junk** in the dropdown list.
7177

7278
> [!div class="mx-imgBorder"]
7379
> :::image type="content" source="media/owa-report-as-not-junk.png" alt-text="The results of selecting the Report button after selecting multiple messages in the Junk Email folder in Outlook on the web." lightbox="media/owa-report-as-not-junk.png":::
@@ -77,10 +83,9 @@ Based on the [User reported settings](submissions-user-reported-messages-custom-
7783
## Use the Report Message and Report Phishing add-ins in Outlook
7884

7985
- The procedures in this section require the Microsoft Report Message or Report Phishing add-ins. For more information, see [Enable the Microsoft Report Message or the Report Phishing add-in](submissions-users-report-message-add-in-configure.md) installed.
80-
8186
- The versions of Outlook that are supported by the Report Message and Report Phishing add-ins are described [here](submissions-users-report-message-add-in-configure.md#what-do-you-need-to-know-before-you-begin).
8287

83-
### Use the Report Message add-in to report junk and phishing messages in Outlook
88+
### Use the Report Message add-in to report junk and phishing messages
8489

8590
- Users can report a message as junk from the Inbox or any email folder other than the Junk Email folder.
8691
- Users can report a message as phishing from any email folder.
@@ -105,7 +110,7 @@ Based on the [user reported settings](submissions-user-reported-messages-custom-
105110
- **Reported as junk**: The messages are moved to the Junk Email folder.
106111
- **Reported as phishing**: The messages are deleted.
107112

108-
### Use the Report Message add-in to report messages that aren't junk in Outlook
113+
### Use the Report Message add-in to report messages that aren't junk
109114

110115
1. In Outlook, open a message in the Junk Email folder.
111116
2. Do one of the following steps based on your **Ribbon Layout** configuration in Outlook:

defender-office-365/submissions-report-messages-files-to-microsoft.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ Watch this video that shows more information about the unified submissions exper
4646
4747
|Method|Submission type|Comments|
4848
|---|---|---|
49-
|[The built-in Report button](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook-on-the-web)|User|Currently, this method is available only in Outlook on the web (formerly known as Outlook Web App or OWA).|
49+
|[The built-in Report button in supported versions of Outlook](submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook)|User||
5050
|[The Microsoft Report Message and Report Phishing add-ins](submissions-outlook-report-messages.md#use-the-report-message-and-report-phishing-add-ins-in-outlook)|User|These free add-ins work in Outlook on all available platforms. For installation instructions, see [Enable the Report Message or the Report Phishing add-ins](submissions-users-report-message-add-in-configure.md).|
5151
|[The Submissions page in the Microsoft Defender portal](submissions-admin.md)|Admin|Admins can report good (false positives) and bad (false negative) messages, email attachments, and URLs (entities) from the available tabs on the **Submissions** page. <br><br> Admins can also submit user reported messages from the **User reported** tab on the **Submissions** page to Microsoft for analysis. The **Submissions** page is available only in organizations with Exchange Online mailboxes as part of a Microsoft 365 subscription (not available in standalone EOP).|
5252
|Report messages from quarantine|Admin and User|Admins can [submit quarantined messages to Microsoft for analysis](quarantine-admin-manage-messages-files.md#report-email-to-microsoft-for-review-from-quarantine) (false positives and false negatives). <br><br> If users are allowed to [release their own messages from quarantine](quarantine-end-user.md#release-quarantined-email), and [user reported settings](submissions-user-reported-messages-custom-mailbox.md) is configured to allow users to report quarantined messages, users can select **Report message as having no threats** (false positive) when they release a quarantined message.|

0 commit comments

Comments
 (0)