kennysarmy Posted September 10, 2021 Posted September 10, 2021 Last academic year we ran a successful round of phishing training videos from Sophos Phish Threat, this academic year we've had problems with Microsoft blocking the emails. Is there anything else I need to edit to allow [email protected] through all the various Office 365 email checks?
Cat_Jam148 Posted September 10, 2021 Posted September 10, 2021 (edited) I also tend to set the following mail flow rule: Edited September 10, 2021 by Cat_Jam148 2
Koldov Posted September 10, 2021 Posted September 10, 2021 We had this problem with the exact same scenario... Unfortunately our O365 tenancy is from a 3rd party provider (they put a front end on it) therefore everything has to go through their support and they were reasonably helpful but we didn't manage to get to the bottom of it. They were also in the middle of some big change rollout, so I think we were dumped at the bottom of a long list of issues. Something changed with O365 and they decided to implement 'Secure by Default': https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/secure-by-default?view=o365-worldwide Obviously what I was trying to do would relax the security, but Sophos give lots of domains and such to whitelist but we still couldn't get it to work (or when it did they went straight to the junk folder anyway with disabled links etc). Looking for a good, straight-forward, comprehensive set of rules and such that I can just email to them and have it work (just for once please)! 1
kennysarmy Posted September 10, 2021 Author Posted September 10, 2021 I also tend to set the following mail flow rule: [ATTACH=CONFIG]63010[/ATTACH] Thanks - will add this one too
kennysarmy Posted September 10, 2021 Author Posted September 10, 2021 I presume this takes a while as I've just tried a test email from Sophos and it's still getting trapped by the spam filter again.
kennysarmy Posted September 10, 2021 Author Posted September 10, 2021 We had this problem with the exact same scenario... Unfortunately our O365 tenancy is from a 3rd party provider (they put a front end on it) therefore everything has to go through their support and they were reasonably helpful but we didn't manage to get to the bottom of it. They were also in the middle of some big change rollout, so I think we were dumped at the bottom of a long list of issues. Something changed with O365 and they decided to implement 'Secure by Default': https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/secure-by-default?view=o365-worldwide Obviously what I was trying to do would relax the security, but Sophos give lots of domains and such to whitelist but we still couldn't get it to work (or when it did they went straight to the junk folder anyway with disabled links etc). Looking for a good, straight-forward, comprehensive set of rules and such that I can just email to them and have it work (just for once please)! That document you link states: In August 2021, secure by default will be extended to Exchange mail flow rules (also known as transport rules). If you use mail flow rules to allow third-party phishing simulations or unfiltered delivery to security operation mailboxes, you eventually need to eliminate these rules and switch to using the advanced delivery policy when the feature is available to you. I can't make head nor tail of the advanced delivery policy document when it comes to just allow Sophos emails through https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/configure-advanced-delivery?view=o365-worldwide We don't have Security operations (SecOps) mailboxes nor use Microsoft 365 Defender.
kennysarmy Posted September 10, 2021 Author Posted September 10, 2021 The only way around it I can see is to each morning / afternoon review the emails in quarantine https://security.microsoft.com/quarantine and then release those which I know to be from Sophos. How rubbish is that?
psydii Posted September 10, 2021 Posted September 10, 2021 Could you not use 365's built in capabilities for this? https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training?view=o365-worldwide
kennysarmy Posted September 10, 2021 Author Posted September 10, 2021 Could you not use 365's built in capabilities for this? https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training?view=o365-worldwide Applies to Microsoft Defender for Office 365 plan 2 So I guess No. 1
Koldov Posted September 10, 2021 Posted September 10, 2021 Well, I've sent a few emails... we will see. I'll keep you updated (or if you work it out before, please let me know). I've contacted our gFL as they 'sold' the product to us and support it (or can raise it with Sophos) and I've emailed our 3rd party email provider who should also support us (although this isn't something they 'need' to support us with - so I'm not holding my breath)...
kennysarmy Posted September 10, 2021 Author Posted September 10, 2021 Well, I've sent a few emails... we will see. I'll keep you updated (or if you work it out before, please let me know). I've contacted our gFL as they 'sold' the product to us and support it (or can raise it with Sophos) and I've emailed our 3rd party email provider who should also support us (although this isn't something they 'need' to support us with - so I'm not holding my breath)... I've raised a ticket with Sophos, Office 365 will be one of the main email providers so I'd expect them to provide the instructions to make it work with that system! I'll keep you posted. Case ref: is 04392518 if you wish to refer to it in any of your correspondence with Sophos. 1
free780 Posted September 10, 2021 Posted September 10, 2021 (edited) Sounds like this needs configuring. https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/configure-advanced-delivery?view=o365-worldwide#use-the-microsoft-365-defender-portal-to-configure-third-party-phishing-simulations-in-the-advanced-delivery-policy Edited September 10, 2021 by free780
kennysarmy Posted September 13, 2021 Author Posted September 13, 2021 Sounds like this needs configuring. https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/configure-advanced-delivery?view=o365-worldwide#use-the-microsoft-365-defender-portal-to-configure-third-party-phishing-simulations-in-the-advanced-delivery-policy Microsoft 365 Defender portal - don't have access to the settings they state. No subscriptions found Before you can start using Microsoft Defender for Endpoint, you need to subscribe to the service SeeMicrosoft Defender for Endpoint product siteor contact your Microsoft account team for information. Already subscribed to a trial or commercial license? Microsoft Defender for Endpoint license settlement can take up to 30 minutes. Please try to log in again later. Need further assistance? Contact support Click here to retry now
kennysarmy Posted September 13, 2021 Author Posted September 13, 2021 I've managed to get to the advanced delivery part of MS Security: https://security.microsoft.com/advanceddelivery?viewid=PhishingSimulation But it only seems to allow a max. of 10 sending domains. Sophos Phish Threat seems to have a lot more than 10 https://support.sophos.com/support/s/article/KB-000037983?language=en_US#anchor3 What to do To ensure successful delivery of Phish Threat emails, include the following IP addresses in the allow list: 54.240.51.52 54.240.51.53 The domains below must also be allowed in your environment to ensure the successful completion of your Phish Threat campaigns. Domain name auditmessages.com bankfraudalerts.com buildingmgmt.info corporate-realty.co court-notices.com e-billinvoices.com e-documentsign.com e-faxsent.com e-receipts.co epromodeals.com fakebookalerts.live global-hr-staff.com gmailmsg.com helpdesk-tech.com hr-benefits.site it-supportdesk.com linkedn.co mail-sender.online myhr-portal.site online-statements.site outlook-mailer.com secure-bank-alerts.com shipping-updates.com tax-official.com toll-citations.com trackshipping.online voicemailbox.online 1
kennysarmy Posted September 13, 2021 Author Posted September 13, 2021 Advanced Delivery set to allow Sophos sending domain : auditmessages.com Still gets trapped
Koldov Posted September 13, 2021 Posted September 13, 2021 I found exactly the same when trying to configure that late on Friday afternoon, so I gave up (again)! "The improved Microsoft 365 Defender portal is now available. This new experience brings Defender for Endpoint, Defender for Office 365, Microsoft 365 Defender, and more into the Microsoft 365 security center." Can't blame MS for trying to be more security conscious 'by default', but strange you can't then configure it without a license...
Koldov Posted September 13, 2021 Posted September 13, 2021 (edited) Is there a difference between the fact that it has labelled it as a 'High Confidence Phish', but then the 'policy' it is using is an anti-spam one? Do you have the domains configured in the anti-spam policy (were they left as configured from the previous efforts to allow a Phish campaign)? Also, how do you know which domain a certain campaign is going to be sent from? EDIT: It seems our 3rd party email provider put the domains in here and the IPs in 'Connection Filter Policy'. I haven't tried putting anything in the 'Advanced' section yet (as I couldn't fit more than 10 domains in either), but I wonder if it's using bits of both the rules and the 'advanced' section? Edited September 13, 2021 by Koldov
Koldov Posted September 13, 2021 Posted September 13, 2021 Sorry, I see in your OP you put '[email protected]' in the anti-spam policy... Where did you get that from? I haven't seen that in the documentation. Is that something like a main 'sending domain' or something?
kennysarmy Posted September 13, 2021 Author Posted September 13, 2021 Sorry, I see in your OP you put '[email protected]' in the anti-spam policy... Where did you get that from? I haven't seen that in the documentation. Is that something like a main 'sending domain' or something? We tend to do a few weeks of training then a simulated attack. The emails advising of the training come from : [email protected] 1
kennysarmy Posted September 13, 2021 Author Posted September 13, 2021 Is there a difference between the fact that it has labelled it as a 'High Confidence Phish', but then the 'policy' it is using is an anti-spam one? Do you have the domains configured in the anti-spam policy (were they left as configured from the previous efforts to allow a Phish campaign)? [ATTACH=CONFIG]63042[/ATTACH] Also, how do you know which domain a certain campaign is going to be sent from? EDIT: It seems our 3rd party email provider put the domains in here and the IPs in 'Connection Filter Policy'. I haven't tried putting anything in the 'Advanced' section yet (as I couldn't fit more than 10 domains in either), but I wonder if it's using bits of both the rules and the 'advanced' section? >> Also, how do you know which domain a certain campaign is going to be sent from? When you create the campaign there is a section to choose the email address of the sender. I've been doing all my testing with it set to : [email protected] I think I've managed to get it so that the training email address is unfiltered - but I can't see to get the same for the [email protected] emails. YET! 1
kennysarmy Posted September 13, 2021 Author Posted September 13, 2021 If anyone can help analyse the message header I could send one via PM
kennysarmy Posted September 13, 2021 Author Posted September 13, 2021 My 3 rules in place to try and allow emails from : [email protected] (one of the Sophos Phish test addresses)
Koldov Posted September 13, 2021 Posted September 13, 2021 The strange thing is, as I've been looking through Google I came across this: https://support.knowbe4.com/hc/en-us/articles/4404511190803-How-to-Use-Advanced-Delivery-Policies-in-Microsoft-365 Basically it seems to suggest (or at least the way they do it does) that there should be some sort of primary domain and then the individual senders are placed in the 'Simulation URL' section...
Koldov Posted September 13, 2021 Posted September 13, 2021 Could you change something here and see if the behaviour changes (just to confirm that it is or isn't something in this policy that is blocking).
kennysarmy Posted September 13, 2021 Author Posted September 13, 2021 Could you change something here and see if the behaviour changes (just to confirm that it is or isn't something in this policy that is blocking). [ATTACH=CONFIG]63047[/ATTACH] Hi, possibly but back in June/July everything was working fine - it's only Microsoft's Improvements that have broken things - - - Updated - - - I've fired another email off to Sophos to ask if they can offer some better advice than just pointing to Microsoft articles!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now