The following instruction allow IP Addresses used in phishing awareness campaigns created with LibraCyber PhishBrain.
Add LibraCyber PhishBrain IP Addresses and Sending domain
-
From the Microsoft 365 Admin Center, click Security under Admin centers. Or, you can directly log in to your Microsoft 365 Defender portal.
-
Under the Email & Collaboration section, select Policies & Rules
- Navigate to Threat policies > Advanced delivery
-
On the Advanced delivery page, select the Phishing Simulation tab.
- Click the Edit icon.
- In the Edit third-party phishing simulation modal, adjust the following settings:
- Click Save
Note
If your MX record doesn't point to Microsoft 365, the IP address in the Authentication-results header must match the IP address in the advanced delivery policy. If the IP addresses don't match, you might need to configure Enhanced Filtering for Connectors so the correct IP address is detected.
If you're using the Built-in protection preset security policy or your custom Safe Links policies have the setting Do not rewrite URLs, do checks via SafeLinks API only enabled, time of click protection doesn't treat phishing simuation links in email as threats in Outlook on the web, Outlook for iOS and Android, Outlook for Windows v16.0.15317.10000 or later, and Outlook for Mac v16.74.23061100 or later. If you're using older versions of Outlook, consider disabling the Do not rewrite URLs, do checks via SafeLinks API only setting in custom Safe Links policies.
Adding phishing simulation URLs to the Do not rewrite the following URLs in email section in Safe Links policies might result in unwanted alerts for URL clicks. Phishing simulation URLs in email messages are automatically allowed both during mail flow and at time of click.
More info here (https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/configure-advanced-delivery?view=o365-worldwide#use-the-microsoft-365-defender-portal-to-configure-third-party-phishing-simulations-in-the-advanced-delivery-policy)