Skip to content

Commit d804637

Browse files
authored
Update attack-simulation-training-faq.md
1 parent 7923a70 commit d804637

File tree

1 file changed

+10
-10
lines changed

1 file changed

+10
-10
lines changed

defender-office-365/attack-simulation-training-faq.md

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ ms.custom:
1919
- seo-marvel-apr2020
2020
description: Admins can learn about deployment considerations and frequently asked questions regarding Attack simulation and training in Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 organizations.
2121
ms.service: defender-office-365
22-
ms.date: 09/23/2024
22+
ms.date: 10/22/2024
2323
appliesto:
2424
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 2</a>
2525
---
@@ -96,20 +96,20 @@ Either way, it's important to use different payloads to avoid discussion and ide
9696

9797
By default, Outlook is configured to block automatic image downloads in messages from the internet. Although you can [configure Outlook to automatically download images](https://support.microsoft.com/office/15e08854-6808-49b1-9a0a-50b81f2d617a), we don't recommend it due to the security implications (potential automatic download of malicious code or web bugs, also known as web beacons or tracking pixels).
9898

99-
### I see clicks or compromise events from users who insist they didn't click the link in the simulation message OR I am seeing clicks within a few seconds of delivery for many of my users. (False positives)
99+
### I see clicks or compromise events from users who insist they didn't click the link in the simulation message OR I am seeing clicks within a few seconds of delivery for many of my users (false positives). What's going on?
100100

101-
These events can occur when there are security devices, or applications that might be inspecting the mail, some of which may include (but not limited to):
101+
These events can occur when additional security devices or applications inspect simulation messages. For example (but not limited to):
102102

103-
- Applications/plugins within outlook that inspect/intercept the message
104-
- Email security applications
105-
- Endpoint security or antivirus software
106-
- SOAR playbooks that auto-triage/auto-respond to reported messages
103+
- Applications or plugins within Outlook that inspect or intercept the message.
104+
- Email security applications.
105+
- Endpoint security or anti-virus software.
106+
- Security orchestration, automation and response (SOAR) playbooks that automatically triage or automatically respond to reported messages.
107107

108-
These kind of applications can look at the website content for the purpose of detecting real phish, and you will need to define exclusions for simulation messages.
108+
These types of applications can look at web content to detecting phishing, so you need to define exclusions for simulation messages in these applications.
109109

110-
Looking through different fields like IP (e.g. EmailLinkClicked_IP) and TimeStamp (e.g. EmailLinkClicked_TimeStamp) may give more details about the event. e.g. if a click occured within a few seconds of delivery, and it is a non-Microsoft IP or not your company/user's IP, then it is likely that a third-party filtering system or another service is intercepting the message.
110+
EmailLinkClicked_IP and EmailLinkClicked_TimeStamp data might give more details about the event. For example, if a click occured a few seconds after delivery, and the IP address doesn't belong to Microsoft, your company, or the user, then it's likely that a third-party filtering system or another service intercepted the message.
111111

112-
For any non-Microsoft filtering systems or service that you use, you need to allow or exempt the following items:
112+
For any non-Microsoft filtering systems or services, you need to allow or exempt the following items:
113113

114114
- All [Attack simulation training URLs](attack-simulation-training-get-started.md#simulations) and the corresponding domains. Currently, we don't send simulation messages from a static list of IP addresses.
115115
- Any other domains that you use in custom payloads.

0 commit comments

Comments
 (0)