This article outlines the configuration options and user features that make up the pre-delivery teachable moments flow for SMTP deployments. It also details the steps for existing customers to migrate to these settings.
Pre-Delivery Settings
The pre-delivery settings page is divided into the following sections:
- Banners
- Banner Configuration
- Phishing Simulation Tests
- Quarantine
- Email Productivity
- Abuse Mailbox
Banners
Banners are contextual, color-coded HTML warning messages that Defend inserts directly into an email. They alert users immediately to the level of risk before they even open it. This feature is the SMTP equivalent of the Microsoft Outlook category tags used in Graph API deployments. For SMTP, there's no separate notification email. The banner itself is the teachable moment.
The following banner types are available:
- External
- Sensitive Details
- Impersonation
- Dangerous
- First Time Sender
- Financial
- Suspicious
For each banner, choose one of the following delivery options:
- Always: Defend adds the banner to every email that matches its criteria, regardless of the email's threat verdict.
- Only if the email is suspicious: Defend adds the banner only to emails that Defend also assess as Suspicious or Dangerous.
Banner Configuration
Choose which banner types are used, and enable or disable silent mode. You can also choose whether banners and link rewrites are retained on internal forwards.
Phishing Simulation Tests
This setting doesn't change how Defend detects phishing simulation tests. It only changes how a detected test is classified. Choose how Defend classifies phishing simulation emails:
- Disabled (default): Defend classifies the email as it normally would.
- Benign: Applies External-level banners and actions to the email.
- Suspicious: Applies Suspicious-level banners and actions to the email.
- Dangerous: Applies Dangerous-level banners and actions to the email.
For recommended configuration guidance, see the Defend | Pre-Delivery Best Practices for Phishing Simulation Tests article.
Quarantine
Select what action to take, before and after delivery, when emails are classified as dangerous or highly dangerous. Pre-delivery quarantine routes incoming emails to Microsoft's quarantine system before they reach the inbox. This feature means users won't get the benefit of Defend's banners for those emails. Post-delivery quarantine remediates emails already in the inbox using the Set Verdict API. Phishing simulation test emails are always excluded from quarantine.
For the full list of quarantine options, see the Defend | Pre-Delivery Settings article.
Email Productivity
Email productivity controls consist of graymail and spam management, letting admins control the level of disturbance users receive from graymail and spam emails.
- Graymail: Enable graymail management, and configure whether these messages are moved out of the inbox, whether banners are inserted, and whether users can report graymail.
- Spam: Enable spam management, and configure whether these messages are moved out of the inbox, whether banners are inserted, and whether users can report spam.
Folder-Move Preferences
When Email Productivity is enabled, users can register their graymail and spam preferences by moving emails between folders in Microsoft Outlook without visiting the Email Summary page.
| Folder-Move | Registered Preference |
|---|---|
| _Graymail to Inbox | Not graymail |
| Inbox to _Graymail | Graymail |
| Junk to Inbox | Not spam |
| Inbox to Junk | Spam |
Preferences are applied at the sender level and are treated the same as preferences set via the Email Summary page or the Phish Alert Button (PAB).
Abuse Mailbox
Enter the address the Defend console should monitor for the abuse mailbox and select whether emails should be automatically remediated.
If you're using KSAT phishing simulation tests alongside the abuse mailbox, additional PAB configuration is required. See the Defend | Pre-Delivery Best Practices for Phishing Simulation Tests article for setup steps.
User Experience
This section outlines the user-facing features added as part of the pre-delivery teachable moments flow.
Banner Categories
The following banner categories are available:
- External
- Sensitive Details
- Impersonation
- Dangerous
- First Time Sender
- Financial
- Suspicious
- Graymail
- Spam
Unlike Graph API deployments, SMTP doesn't send a separate threat notification email. The banner inserted into the original email is the complete teachable moment.