logo
search
Security Policy Errors

How to Stop Microsoft Defender from Marking Phishing Simulations as Threats

Phi Hung VoPhi Hung Vo Oct 1, 2026 868 views

Question details

The user needs to prevent Microsoft Defender from classifying authorized phishing simulation emails as real threats when reported by employees.

How to Stop Microsoft Defender from Marking Phishing Simulations as Threats
Product
Microsoft Defender / Outlook
Device & OS
not provided
Scenario
Managing simulated phishing campaigns using third-party tools like KnowBe4 and ensuring accurate security metrics.
Observed behavior
Phishing simulation emails reported through the Outlook Report Phishing button are being treated as genuine threats, which interferes with simulation reporting workflows and creates false positive alerts.
Before you start

Ensure you have Microsoft 365 Defender administrative credentials and the specific domain names, IP addresses, and simulation URLs provided by your phishing simulation vendor (e.g., KnowBe4).

Solution 1Recommended

Configure Advanced Delivery Policies for Phishing Simulations

Set up Microsoft Defender to recognize and allow authorized phishing simulations, preventing them from triggering false positive security alerts.

Microsoft recommends using the Advanced Delivery policy rather than traditional Exchange mail flow rules to bypass filtering for phishing simulations. This ensures security features are not inadvertently disabled while properly handling your vendor's simulation campaigns.

1
Access the Defender Portal

Open the Microsoft 365 Defender portal and log in with an administrator account. Navigate to 'Policies & rules' and select 'Threat policies'.

2
Open Advanced Delivery Settings

Under the 'Rules' section, locate and click on 'Advanced delivery'.

3
Add Phishing Simulation Details

Select the 'Phishing simulation' tab and click 'Add' or 'Edit' to configure your third-party provider settings.

4
Enter Vendor Information

Input the sending domain, sender IP addresses, and the specific simulation URLs provided by your simulation vendor (such as KnowBe4).

5
Save and Confirm

Click 'Save'. Verify with your vendor support that the configuration aligns with their current infrastructure to ensure simulations are successfully recognized.

Configure Advanced Delivery Policies for Phishing Simulations
Custom Notifications: Once configured, you can set up custom notifications to automatically thank users for correctly reporting a simulation, without triggering an actual security incident.
Free Microsoft Office alternative

Experience a Seamless and Secure Office Alternative

While configuring enterprise security policies in Microsoft Defender, consider streamlining your team's document workflows with WPS Office. It provides a lightweight, highly compatible alternative to Microsoft Office, ensuring smooth operations without heavy administrative overhead.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install WPS Office: Run the downloaded file and follow the quick installation wizard to set up the suite on your computer.
  3. 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Office files with full formatting retention.
Fully compatible with Microsoft Word, Excel, and PowerPoint file formats (.docx, .xlsx, .pptx).Robust local document security features to keep your sensitive enterprise files safe.Lightweight installation that runs smoothly on both older and modern enterprise devices.Familiar user interface allowing for a zero-learning-curve migration for your team.
microsoft office alternative - wps office

Frequently Asked Questions

Why are my KnowBe4 simulation emails triggering Defender alerts?

By default, Microsoft Defender treats all suspicious emails as potential threats. If the sending IPs and domains of your simulation vendor (like KnowBe4) are not explicitly added to the Advanced Delivery policy under the Phishing Simulation tab, Defender will scan and flag them as genuine risks.

Can I use mail flow rules (Exchange transport rules) to bypass filtering for simulations?

Microsoft no longer recommends using traditional mail flow rules to bypass spam filtering for phishing simulations. Instead, you must use the Advanced Delivery policy in the Defender portal to ensure simulations are handled correctly without compromising overall tenant security.

How do users get notified when they report a simulation email in Outlook?

You can configure custom notifications in the Defender portal. When a user reports a message successfully identified as a simulation via the Advanced Delivery policy, the system can send an automated custom email thanking them for correctly identifying a simulated attack.