The Phish Alert Button (PAB) add-in for Exchange 2013/2016 gives your end-users the ability to report suspicious emails and empowers your employees to take an active role in managing the problem of phishing and other types of malicious emails. The tool can also provide your IT or risk management team with early warning of possible phishing attacks or malicious emails so they may take timely and effective actions to prevent security breaches or network compromise.
We encourage you to inform all of your users of this tool before making it accessible. Below are helpful resources that you can use to assist with your implementation of the PAB:
- Best Practices for PAB Implementation (For admins)
- How do I Use the Phish Alert Button for Exchange? (For end-users)
Paid Integration: If you are using our full-featured Phishing and Training console, the PAB will also track if your users report our simulated phishing emails, so you can see which users are successfully identifying potentially malicious emails.
- One of the following mail servers:
- Exchange 2013 - version 15.0.847.32 (SP1) or newer
- Exchange 2016 - version 18.104.22.168 (RTM) or newer
- Office 365
- If you're using Office 365, we recommend installing the Office 365 PAB instead.
- Please note: If your user is using Outlook Online the Exchange version of PAB will not display.
- If you're using OSX High Sierra versions of 10.13.3 or newer, PAB is supported by Mac Outlook 2016.
- In the admin portal, you must enable and configure your PAB. While in the admin portal, you will also need the following item to begin installation:
- ExchangeManifest.xml file (download)
- You must have Optional Connected Experiences connected.
For instructions on how to enable and configure your PAB in the admin portal, visit our main PAB article.
If you are using Internet Explorer, the following steps need to be performed in order for the PAB to run on your PCs:
- Go to the Internet Options section of Internet Explorer and click the Security tab.
- Inside the Internet Sites Zone box, check the Enabled Protected Mode box.
- Click OK.
To enable Optional Connected Experiences in Outlook, follow the instructions below:
- Go to File > Options > Trust Center > Trust Center Settings.
- From Trust Center Settings, go to Privacy Options then Privacy.
- Enable Optional Connected Experiences.
- Microsoft disables the use of add-ins in shared mailboxes and folders. Users will only be able to access the PAB add-in from their primary mailbox.
- This version of the PAB does not support mobile devices. For mobile support, you must install the Office 365 PAB.
- This version of the PAB is supported for Mac Outlook 2016 (up until version 16.23) on OSX High Sierra (version 10.13 or newer). To find out more information, visit our PAB compatibility matrix.
How to Install on Office 365
The below instructions display the Office 365 admin portal. Exchange interfaces will be slightly different.
- Log in to your mail server Admin portal. Under the Settings menu, click Services & add-ins.
- Click Deploy Add-In.
- Click Next to advance through the wizard.
- Select Upload custom apps.
- From the Deploy a new add-in screen, select I have a manifest file (.xlml) on this device then click Choose File.
- The Add From File pop-up window will open. Click the Choose File button. Then, locate and add the ExchangeManifest.xml file from your Account Settings and click the Upload button to install.
- Under Assign Users, make sure that the Everyone option is select. We recommend that you select the Fixed option under Deployment Method, but you can choose any of the other deployment methods.
How the add-in should look once configured in the Exchange area:
If you're installing the PAB add-in on Office 365, it can take up to an hour for the PAB to be visible.
How to Uninstall
- Log in to your mail server Admin portal. Then, navigate to Admin centers > Exchange > dashboard > Services & add-ins
- Select the Phish Alert add-in. Then, click Remove add-in.
Once installed, the PAB add-in will appear as clickable Phish Alert text on any open email.
A user can report any email as a phishing email. The reported email will be in the user's Sent Items as a forwarded message and will be deleted from the user's Inbox. If the user incorrectly reported the email, they can retrieve it from their Deleted items/Trash.
To instruct your users on how to use the PAB, you can provide our How do I use the Phish Alert Button for Exchange? article.
The image above is only for OWA as that version of PAB will also work with the Outlook client as well.
- Video: PAB Installation and User Experience
- How Do I Change the Phish Alert Text for Server-Based PAB (Exchange & Office 365)
- Multiple Phish Alert Button Instances (Multi-PAB): Office 365/Exchange
- PAB Compatibility Matrix