Jump to content

Sophos Phish Training emails being quarantined by Office 365 :(


Recommended Posts

Posted

Last academic year we ran a successful round of phishing training videos from Sophos Phish Threat, this academic year we've had problems with Microsoft blocking the emails.

 

quara.JPG

 

antispaminbound.JPG

 

allowedsenders.JPG

 

 

Is there anything else I need to edit to allow [email protected] through all the various Office 365 email checks?

Posted

We had this problem with the exact same scenario...

 

Unfortunately our O365 tenancy is from a 3rd party provider (they put a front end on it) therefore everything has to go through their support and they were reasonably helpful but we didn't manage to get to the bottom of it. They were also in the middle of some big change rollout, so I think we were dumped at the bottom of a long list of issues.

 

Something changed with O365 and they decided to implement 'Secure by Default':

 

https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/secure-by-default?view=o365-worldwide

 

Obviously what I was trying to do would relax the security, but Sophos give lots of domains and such to whitelist but we still couldn't get it to work (or when it did they went straight to the junk folder anyway with disabled links etc).

 

Looking for a good, straight-forward, comprehensive set of rules and such that I can just email to them and have it work (just for once please)!

  • Thanks 1
Posted
We had this problem with the exact same scenario...

 

Unfortunately our O365 tenancy is from a 3rd party provider (they put a front end on it) therefore everything has to go through their support and they were reasonably helpful but we didn't manage to get to the bottom of it. They were also in the middle of some big change rollout, so I think we were dumped at the bottom of a long list of issues.

 

Something changed with O365 and they decided to implement 'Secure by Default':

 

https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/secure-by-default?view=o365-worldwide

 

Obviously what I was trying to do would relax the security, but Sophos give lots of domains and such to whitelist but we still couldn't get it to work (or when it did they went straight to the junk folder anyway with disabled links etc).

 

Looking for a good, straight-forward, comprehensive set of rules and such that I can just email to them and have it work (just for once please)!

 

 

That document you link states:

 

In August 2021, secure by default will be extended to Exchange mail flow rules (also known as transport rules). If you use mail flow rules to allow third-party phishing simulations or unfiltered delivery to security operation mailboxes, you eventually need to eliminate these rules and switch to using the advanced delivery policy when the feature is available to you.

 

I can't make head nor tail of the advanced delivery policy document when it comes to just allow Sophos emails through :(

 

https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/configure-advanced-delivery?view=o365-worldwide

 

We don't have Security operations (SecOps) mailboxes nor use Microsoft 365 Defender.

Posted

Well, I've sent a few emails... we will see.

 

I'll keep you updated (or if you work it out before, please let me know).

 

I've contacted our gFL as they 'sold' the product to us and support it (or can raise it with Sophos) and I've emailed our 3rd party email provider who should also support us (although this isn't something they 'need' to support us with - so I'm not holding my breath)...

Posted
Well, I've sent a few emails... we will see.

 

I'll keep you updated (or if you work it out before, please let me know).

 

I've contacted our gFL as they 'sold' the product to us and support it (or can raise it with Sophos) and I've emailed our 3rd party email provider who should also support us (although this isn't something they 'need' to support us with - so I'm not holding my breath)...

 

 

I've raised a ticket with Sophos, Office 365 will be one of the main email providers so I'd expect them to provide the instructions to make it work with that system!

 

I'll keep you posted.

 

Case ref: is 04392518 if you wish to refer to it in any of your correspondence with Sophos.

  • Thanks 1
Posted

 

Microsoft 365 Defender portal - don't have access to the settings they state.

 

No subscriptions found

Before you can start using Microsoft Defender for Endpoint, you need to subscribe to the service

SeeMicrosoft Defender for Endpoint product siteor contact your Microsoft account team for information.

 

Already subscribed to a trial or commercial license?

Microsoft Defender for Endpoint license settlement can take up to 30 minutes. Please try to log in again later.

Need further assistance? Contact support

Click here to retry now

Posted

I've managed to get to the advanced delivery part of MS Security:

 

https://security.microsoft.com/advanceddelivery?viewid=PhishingSimulation

 

But it only seems to allow a max. of 10 sending domains.

 

Sophos Phish Threat seems to have a lot more than 10 :(

https://support.sophos.com/support/s/article/KB-000037983?language=en_US#anchor3

 

What to do

To ensure successful delivery of Phish Threat emails, include the following IP addresses in the allow list:

54.240.51.52

54.240.51.53

The domains below must also be allowed in your environment to ensure the successful completion of your Phish Threat campaigns.

 

Domain name

auditmessages.com

bankfraudalerts.com

buildingmgmt.info

corporate-realty.co

court-notices.com

e-billinvoices.com

e-documentsign.com

e-faxsent.com

e-receipts.co

epromodeals.com

fakebookalerts.live

global-hr-staff.com

gmailmsg.com

helpdesk-tech.com

hr-benefits.site

it-supportdesk.com

linkedn.co

mail-sender.online

myhr-portal.site

online-statements.site

outlook-mailer.com

secure-bank-alerts.com

shipping-updates.com

tax-official.com

toll-citations.com

trackshipping.online

voicemailbox.online

  • Thanks 1
Posted

I found exactly the same when trying to configure that late on Friday afternoon, so I gave up (again)!

 

"The improved Microsoft 365 Defender portal is now available. This new experience brings Defender for Endpoint, Defender for Office 365, Microsoft 365 Defender, and more into the Microsoft 365 security center."

 

Can't blame MS for trying to be more security conscious 'by default', but strange you can't then configure it without a license...

Posted (edited)

Is there a difference between the fact that it has labelled it as a 'High Confidence Phish', but then the 'policy' it is using is an anti-spam one?

 

Do you have the domains configured in the anti-spam policy (were they left as configured from the previous efforts to allow a Phish campaign)?

 

phish.jpg

 

Also, how do you know which domain a certain campaign is going to be sent from?

 

EDIT: It seems our 3rd party email provider put the domains in here and the IPs in 'Connection Filter Policy'.

 

I haven't tried putting anything in the 'Advanced' section yet (as I couldn't fit more than 10 domains in either), but I wonder if it's using bits of both the rules and the 'advanced' section?

Edited by Koldov
Posted
Sorry, I see in your OP you put '[email protected]' in the anti-spam policy...

 

Where did you get that from? I haven't seen that in the documentation.

 

Is that something like a main 'sending domain' or something?

 

We tend to do a few weeks of training then a simulated attack.

 

The emails advising of the training come from : [email protected]

  • Thanks 1
Posted
Is there a difference between the fact that it has labelled it as a 'High Confidence Phish', but then the 'policy' it is using is an anti-spam one?

 

Do you have the domains configured in the anti-spam policy (were they left as configured from the previous efforts to allow a Phish campaign)?

 

[ATTACH=CONFIG]63042[/ATTACH]

 

Also, how do you know which domain a certain campaign is going to be sent from?

 

EDIT: It seems our 3rd party email provider put the domains in here and the IPs in 'Connection Filter Policy'.

 

I haven't tried putting anything in the 'Advanced' section yet (as I couldn't fit more than 10 domains in either), but I wonder if it's using bits of both the rules and the 'advanced' section?

 

>> Also, how do you know which domain a certain campaign is going to be sent from?

 

When you create the campaign there is a section to choose the email address of the sender.

 

I've been doing all my testing with it set to : [email protected]

 

I think I've managed to get it so that the training email address is unfiltered - but I can't see to get the same for the [email protected] emails. YET!

  • Thanks 1
Posted

Could you change something here and see if the behaviour changes (just to confirm that it is or isn't something in this policy that is blocking).

 

PHISH 3.jpg

Posted
Could you change something here and see if the behaviour changes (just to confirm that it is or isn't something in this policy that is blocking).

 

[ATTACH=CONFIG]63047[/ATTACH]

 

Hi, possibly but back in June/July everything was working fine - it's only Microsoft's Improvements that have broken things :(

 

- - - Updated - - -

 

I've fired another email off to Sophos to ask if they can offer some better advice than just pointing to Microsoft articles!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...