LogoLogo
Get Demo
  • đź’«NEXT-GENERATION PRODUCT
    • Introduction
    • Getting Started
      • 1. Invite System Users
      • 2. Add Target Users
        • Add Users via CSV
        • Add users via SCIM
          • SCIM Setup in Azure AD
          • SCIM Setup in Okta
          • SCIM Setup in Onelogin
          • SCIM Setup in Jumpcloud
        • Add users via LDAP
        • Add Users via API
      • 3. Email Deliverability
        • Microsoft 365
          • M365: Direct Email Creation
          • M365: Whitelisting
        • Google Workspace
          • Google: Direct Email Creation
          • Google: Whitelisting
        • Exchange 2013 and 2016
      • 4. Track Opened Emails
      • 5. Allow Phishing URLs
        • Whitelist for Office 365
        • Whitelist for Google Workspace
        • Whitelist for Exchange 2013/2016
        • Whitelist in Security Solutions
      • 6. Setup Phishing Reporter
        • Step 1. Download Phishing Reporter
        • Step 2. Deploy Phishing Reporter
          • How to Deploy Add-In in Microsoft 365
          • How to Deploy Add-In in Exchange Admin Center
          • How to Deploy Add-In in Google Workspace
          • How to Deploy Add-In in Outlook
            • Troubleshooting Phishing Reporter Add-In on Outlook Desktop
      • 7. Incident Responder Setup
        • Step 1. Integrate Threat Intel Partners
        • Step 2. Mail Configurations
          • Microsoft 365
          • Google Workspace (Gsuite)
          • Exchange (EWS)
    • Platform
      • Dashboard
        • Dashboard Widgets
        • Incident Responder Widgets
        • Threat Sharing Widgets
        • Phishing Simulator Widgets
      • Threat Intelligence
      • Email Threat Simulator
        • Start Scan
        • View Scan Report
        • Create Trusted Account on Exchange
        • Start Scan on O365 Email Account
        • Start Scan on Google Workspace Email Account
      • Threat Sharing
        • Communities
        • Incidents
      • Phishing Simulator
        • Manage Phishing Scenarios
          • Phishing Scenarios
          • Email Templates
          • Landing Pages
        • Phishing Campaign Manager
        • Phishing Campaign Reports
        • Settings
          • DNS Services and Domains
          • Exclude IP Address
      • Callback Simulator
        • Manage Callback Scenarios
          • Callback Scenarios
          • Callback Email Templates
          • Callback Templates
        • Callback Campaign Manager
        • Callback Campaign Reports
        • Settings
          • Callback Phone Numbers
      • Vishing Simulator
        • Vishing Templates
        • Vishing Campaign Manager
        • Vishing Campaign Reports
      • Smishing Simulator
        • Manage Smishing Scenarios
          • Smishing Scenarios
          • Text Message Templates
          • Landing Page Templates
        • Smishing Campaign Manager
        • Smishing Campaign Reports
        • Settings
          • Manage DNS and Domains
          • Exclude IP Addresses
      • Quishing Simulator
        • Manage Quishing Scenarios
          • Quishing Scenarios
          • Quishing Templates
          • Quishing Landing Page Templates
        • Quishing Campaign Manager
        • Quishing Campaign Reports
        • Settings
          • DNS and Domains
          • Excluding IP Address
      • Awareness Educator
        • Training Library
        • Enrollments
        • Certificates
        • Training Reports
        • Training Completion Queries
      • Incident Responder
        • Incident Responder Dashboard
        • Investigations
        • Integrations
        • Playbook
        • Mail Configurations
          • Microsoft 365
          • Exchange
          • Google Workspace
        • Cross Company Integration
      • Phishing Reporter
        • Phishing Reporter Customization
        • Phishing Reporter Deployment
          • How to Deploy the Add-in in Microsoft 365
          • Phishing Reporter Page View Failure Due to Deprecated Exchange Online Tokens
          • Microsoft Ribbon Phishing Reporter
          • Microsoft Page View Phishing Reporter
          • How to Deploy the Add-in in Exchange Admin Center
          • How to Deploy the Add-in in Google Workspace
          • Phishing Reporter Announcement Email Template
        • Diagnostic Tool
        • Integrating Microsoft Phishing Reporting Button with Keepnet
        • Integrating Microsoft Defender with Keepnet Phishing Reporter
        • Troubleshooting Phishing Reporter on Outlook Desktop
      • Reports
        • Advanced Reports
        • Executive Reports
        • Scheduled Reports
        • Gamification Report
      • Company
        • Target Users
        • Companies
          • Company Groups
        • Company Settings
          • Privacy
            • Account Privacy
            • Data Privacy
          • AI Ally Settings
          • SMTP Settings
          • Direct Email Creation
            • Direct Email Creation for Google Workspace
            • Direct Email Creation for Microsoft 365
          • Notification Templates
          • Google User Provisioning
          • REST API
          • White Labeling
          • Proxy Settings
          • SAML Settings
            • How to Configure SAML on ADFS
            • How to Configure SAML on Google Workspace
            • How to Configure SAML on Azure AD
            • How to Configure SAML on CyberArk
            • How to Configure SAML on Okta
          • SCIM Settings
            • Getting Started with SCIM
            • Azure AD SCIM Integration
            • Okta SCIM Integration
            • Onelogin SCIM Integration
            • Jumpcloud SCIM Integration
          • SIEM Integrations
            • Splunk Integration
            • Syslog Integration
          • LDAP
          • Allowed Domains
        • System Users
          • People
          • Roles
        • Audit Log
        • Job Log
      • Free Phishing Email Analysis Service
    • Miscellaneous
      • Whitelisting
        • How to Whitelist an IP Address in Office 365
        • How to Whitelist an IP Address in Exchange 2013 and 2016
        • How to Whitelist an IP Address in Google Workspace
        • How to Whitelist in Mimecast
        • Whitelisting in Other Security Solutions
        • Whitelisting the Pictures on Microsoft Outlook Apps
        • Keepnet Tools Whitelisting Guidelines
        • Understanding Email Delivery Errors
        • Tracking Email Opens in Phishing Simulations
      • User Profile
      • Multi-Factor Authentication (MFA) Settings
      • On-Premise Requirement Checker
      • Platform Requirements
        • Portal UI Requirements
        • Phishing Reporter Requirements
        • Diagnostic Tool Requirements
      • Maintenance Tool
      • Understanding the Preferred Language Setting
  • 📚RESOURCES
    • Platform Security
    • Volume & Performance
    • Customer Help Desk
    • Product Update/Maintenance
    • Research Methodology
    • Release Notes
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
      • 2020
  • ⚖️Legal Hub
    • For Customers
      • Customer Terms of Service
      • Product Specific Terms
      • Jurisdiction Specific Terms
      • Data Processing Agreement
      • Regional Data Hosting Policy
      • Product and Services Catalog
      • Acceptable Use Policy
      • Keepnet Security Program
      • Microsoft CoPilot Usage Policy
    • For Everyone
      • Website
        • Terms of Use
        • Privacy Policy
        • Cookie Policy
      • Free Phishing Email Analysis
        • Terms of Service
        • Privacy Policy
      • Transparency Report
Powered by GitBook

Copyright © Keepnet Labs LTD. All rights reserved.

On this page
  • Steps to Set Up the Integration
  • What Happens When a User Reports a Suspicious Email?

Was this helpful?

Export as PDF
  1. NEXT-GENERATION PRODUCT
  2. Platform
  3. Phishing Reporter

Integrating Microsoft Defender with Keepnet Phishing Reporter

PreviousIntegrating Microsoft Phishing Reporting Button with KeepnetNextTroubleshooting Phishing Reporter on Outlook Desktop

Last updated 1 day ago

Was this helpful?

This integration allows your employees to report suspicious emails using the button, forwarding them to both your SOC team and Microsoft Defender. Additionally, reported emails are sent to , enabling deeper analysis and enhanced tracking while maintaining your current reporting workflow.

Key Benefits:

  • Dual Reporting: Emails reported via the Keepnet Phishing Reporter button are forwarded to both Microsoft Defender and Keepnet’s Incident Responder for comprehensive threat analysis.

  • SOC/IT Reporting: Reported emails are also delivered to the SOC/IT team's mailbox for manual review and internal investigation.

  • Simulation Tracking: During phishing simulations, Keepnet tracks users who report simulation emails, enabling administrators to measure awareness and deliver targeted training.

Microsoft Defender requires that reported emails be in EML format for analysis.

Important Notice: Enabling this integration will automatically disable Microsoft’s native “Report” button. Users will exclusively use the Keepnet Phishing Reporter to report suspicious emails.

Steps to Set Up the Integration

Please follow the steps below.

  1. Log in using your global admin credentials and navigate to the > Settings > Email & collaboration.

  2. Click the User reported settings option in the left-hand panel.

  3. Under the Select an Outlook report button configuration section, choose: ➤ Use a non-Microsoft add-in button.

Important Notice: Choosing this option will automatically disable the Microsoft Report button.

  1. In the Add an Exchange Online mailbox to send reported messages to field, enter the email address, such as your SecOps mailbox or a shared email address.

  2. (Optional) You can enable the Allow reporting for quarantined messages. Only admins can report quarantined Teams messages, which allows your users to report emails from their quarantine folder.

After you have configured these settings in Microsoft 365 Defender, you’ll now need to configure the rest of the settings in the Keepnet platform under the Phishing Reporter menu.

  • Log in to the Keepnet platform.

  • From the left menu, click Phishing Reporter, then go to Settings.

  • Customize your Phishing Reporter button as needed.

  • Click on the Email Settings tab and follow the steps below:

    • Enable the Send information email for reported incidents option.

    • In the Recipient Email Address field, enter the same address used in step 5 of the Microsoft Defender configuration.

    • Optionally, add CC or BCC email addresses to forward reported emails to additional recipients.

    • Customize the Email Subject and Email Body for end-user submissions.

  • After configuring these, click MANAGE AND DOWNLOAD.

  • Click the CONNECT button to authorize Graph API access, so Keepnet Phishing Reporter can work with your Microsoft 365.

  • Upon successful authorization:

    • Download the Ribbon or Page View version of the reporter button as an XML file.

    • Follow the deployment steps below to add the button to users’ Outlook apps.

You can now deploy the Keepnet Phishing Reporter button to test groups or all users using one of the following methods:

What Happens When a User Reports a Suspicious Email?

When an employee reports a suspicious email using the Keepnet Phishing Reporter, the following workflow is triggered:

  1. The email is simultaneously forwarded to Keepnet Incident Responder (if licensed) for advanced case management, automated triage, and analysis.

  2. The same reported email is also sent to SOC/IT teams, as well as any configured CC or BCC recipients, for manual investigation and review.

Microsoft’s Submissions page does not support emails containing multiple attachments. For example, files like header.txt will not be included when forwarded to Microsoft Defender. Only the original email will be analyzed by Microsoft Defender.

Processing Time: Once an employee reports an email, the email will appear on your Microsoft 365 Defender > Submissions page in a few minutes.

If you wish to compare the differences between Ribbon and Page View phishing reporter buttons, please .

The reported email is sent to Microsoft Defender under the page for automated analysis.

đź’«
Keepnet Phishing Reporter
Keepnet’s Incident Responder
Microsoft 365 Defender portal
Deploy Microsoft Ribbon Phishing Reporter
Deploy Microsoft Page View Phishing Reporter
Submissions
click this link