Organizations using Microsoft 365 alongside KnowBe4’s phishing security tests and Defend must complete additional configuration steps to ensure proper email delivery and accurate testing results. This article outlines the recommended best practices for configuring Defend while using phishing security tests.
For instructions on adding Defend's sending IP addresses to an advanced delivery policy in Microsoft 365, see the Defend - KnowBe4 Security Test Emails article.
Tags and Threat Notifications
By default, phishing security tests will be marked with tags, or users will receive a threat notification about them. This default behavior simulates a real-world scenario for how Defend would react to a legitimate phishing email.
If you want to see if users still select phishing emails without tags, you can remove them from any phishing security tests by adding KnowBe4's sending IP addresses to Defend's allowlist. This process will also prevent users from receiving threat notifications for phishing security tests.
For full details, see the Whitelisting Guide and Defend - Allow or Deny Lists article.
Phishing Security Tests
As an alternative to removing tags and threat notifications from phishing security tests entirely, you can use the Phishing Security Tests setting on the Settings page to control which tags and actions are applied instead. For a description of each option, see the Defend | Post-Delivery Settings article.
Setting this to Suspicious or Dangerous will still trigger the other actions configured for that level, such as auto-remediation. This setting doesn't affect detection, and phishing security test emails are still not sent to quarantine.