# Phishing Campaign - Setting Up Microsoft o365

##### <span style="color: rgb(53, 152, 219);">**Why Whitelist in Office 365?**</span>

<span style="color: rgb(0, 0, 0);">Whitelisting ensures the **CyTech - AQUILA Phishing Simulation(PS) Module** functions without issue and prevents PS emails from being automatically moved to the spam folder or notifying users about potential phishing emails. The Connection Filter Policy and Spam Filtering both required to be whitelisted.</span>

##### **<span style="color: rgb(53, 152, 219);">Key Configurations:</span>**

1. <span style="color: rgb(0, 0, 0);">**[Microsoft Defender](https://security.microsoft.com/)**</span>
    - <span style="color: rgb(0, 0, 0);">Whitelist the Connection Filter Policy</span>
    - <span style="color: rgb(0, 0, 0);">Whitelist Using Advanced Delivery Policies</span>
2. <span style="color: rgb(0, 0, 0);">**[Exchange Admin Center](https://admin.exchange.microsoft.com/#/)**</span>
    - <span style="color: rgb(0, 0, 0);">Whitelist Spam Filtering</span>
    - <span style="color: rgb(0, 0, 0);">Whitelist Advanced Threat Protection (ATP)</span>

##### <span style="color: rgb(53, 152, 219);">**Whitelist Connection Filter Policy**</span>

<span style="color: rgb(0, 0, 0);">The Office 365 Exchange Connection Filter identifies good or bad source email servers by their IP addresses. The actions below will allow all emails from CyTech IP addresses to be received.</span>

##### <span style="color: rgb(53, 152, 219);">**Whitelist the Connection Filter Policy** </span>

<span style="color: rgb(0, 0, 0);">1. Login to Microsoft Defender, click here - **[<span style="color: rgb(53, 152, 219);">Microsoft Defender.</span>](https://security.microsoft.com/)**</span>

<span style="color: rgb(0, 0, 0);">2. Navigate through **Email &amp; Collaboration&gt;Policies &amp; Rules&gt;Threat Policies&gt;Anti-spam.**</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/PDl8uDXvhHXHskUW-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/PDl8uDXvhHXHskUW-image.png)</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/4Fah0R9XdAWXbZvU-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/4Fah0R9XdAWXbZvU-image.png)</span>

<span style="color: rgb(0, 0, 0);">3. Click on "**Connection filter policy**". Then click on "**Edit connection filter policy**".</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/qNwcvxjpzdNb3STp-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/qNwcvxjpzdNb3STp-image.png)</span>

<span style="color: rgb(0, 0, 0);">4. Add the **IP's** to the "Always allow messages from the following IP addresses or address range:". Then click the "**Save**" button.</span>

<span style="color: rgb(0, 0, 0);">**Allow IP's: 35.153.237.243**(Mail Server), **107.22.65.180**(Landing Page)</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/MvJvE5Zk2I9lb0Tp-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/MvJvE5Zk2I9lb0Tp-image.png)</span>

##### <span style="color: rgb(53, 152, 219);">**Whitelist Using Advanced Delivery Policies in Microsoft Defender for Office 365**</span>

<span style="color: rgb(0, 0, 0);">Phishing simulations are attacks orchestrated by your security team and used for training and learning. Simulations can help identify vulnerable users and lessen the impact of malicious attacks on your organization.</span>

<span style="color: rgb(0, 0, 0);">Third-party phishing simulations require at least one Sending domain entry \[source domain or DKIM\] AND at least one Sending IP entry. Simulations URLs to allow entries are optional, and prevent the simulated phishing URLs from being blocked at time of click.</span>

<span style="color: rgb(0, 0, 0);"> 1. Go to **Email &amp; Collaboration &gt; Policies &amp; Rules &gt; Threat policies &gt; Advanced delivery in the Rules section**.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/mN1S2kTRaISM8muh-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/mN1S2kTRaISM8muh-image.png)</span>

<span style="color: rgb(0, 0, 0);">2. In the Advanced delivery menu, navigate to the Phishing simulation tab and press Edit to either add new or configure existing values (refer to the screenshot below). After editing all the needed Domain, Sending IP and Simulation URLs to allow**.** Click **"Save".**</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/8y5eyi7HQva7D6au-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/8y5eyi7HQva7D6au-image.png)</span>

<span style="color: rgb(0, 0, 0);">3. On the Edit third-party phishing simulation menu that opens, configure the following settings:</span>

<span style="color: rgb(0, 0, 0);">**Domain:** Expand this setting and enter at least one sending domain specific for campaign by clicking in the box, entering a value, and then pressing Enter or selecting the domains displayed below. Repeat this step as many times as necessary. You can add up to 20 entries.</span>

- <span data-teams="true" style="color: rgb(0, 0, 0);">slackj.com</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">ttrelli.com</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">airbnd.cc</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">attlassians.com</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">eebbey.com</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">lastpasss.net</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">my1psswords.com</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">zooms.cc</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/iUgoti0IotleAb1x-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/iUgoti0IotleAb1x-image.png)</span>

<span style="color: rgb(0, 0, 0);">**Sending IP:** Expand this setting and enter at least one valid IPv4 address by clicking in the box, entering a value, and then pressing Enter or selecting the value that's displayed below the box. Repeat this step as many times as necessary. You can add up to 10 entries.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/Z463XX4cNcj2NV6U-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/Z463XX4cNcj2NV6U-image.png)</span>

<span style="color: rgb(0, 0, 0);">**Simulation URLs to allow:** Expand this setting and optionally enter specific URLs that are part of your phishing simulation campaign that should not be blocked or detonated by clicking in the box, entering a value, and then pressing Enter or selecting the value that's displayed below the box.</span>

<span style="color: rgb(0, 0, 0);">For the URL syntax format, see URL syntax for the Tenant Allow/Block List (opens in a new tab). These URLs are wrapped at the time of the click, but they aren't blocked.</span>

<span style="color: rgb(0, 0, 0);">When you're finished, you can click Add, and click close afterward if this was a first-time addition, or if you were editing existing values click Save and then click Close. </span>

- <span style="color: rgb(0, 0, 0);">[Manage allows and blocks in the Tenant Allow/Block List](https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-about?view=o365-worldwide#url-syntax-for-the-tenant-allowblock-list)</span>

<span style="color: rgb(0, 0, 0);">Refer to these simulation URLs to allow in your campaign:</span>

- <span data-teams="true" style="color: rgb(0, 0, 0);">slackj.com/\*</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">ttrelli.com/\*</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">airbnd.cc/\*</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">attlassians.com/\*</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">eebbey.com/\*</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">lastpasss.net/\*</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">my1psswords.com/\*</span>
- <span data-teams="true" style="color: rgb(0, 0, 0);">zooms.cc/\*</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/2upgxf44qn82hAs8-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/2upgxf44qn82hAs8-image.png)</span>

##### <span style="color: rgb(53, 152, 219);">**Whitelist Spam Filtering**</span>

<span style="color: rgb(0, 0, 0);">All mail systems have spam filtering. As the CyTech PS emails are "phishing: by definition, the Microsoft spam filter must be whitelisted. The steps below outline how to disable all spam checks for CyTech PS emails, so you won't experience issues with 100% clicked and 100% opened emails, even if the users don't click on them.</span>

<span style="color: rgb(0, 0, 0);">**Steps to Whitelist the Spam Filtering** </span>

<span style="color: rgb(53, 152, 219);"><span style="color: rgb(0, 0, 0);">1. Login to Exchange Admin Center, click here -</span> **[Exchange Admin Center.](https://admin.exchange.microsoft.com/#/)**</span>

<span style="color: rgb(0, 0, 0);">2. Navigate through **Mail flow&gt;Rules&gt;+Add a rule&gt;"Create a new rule"**.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/hAk8OrVkreZ6pU04-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/hAk8OrVkreZ6pU04-image.png)</span>

<span style="color: rgb(0, 0, 0);">3. Give the rule a name, such as "**CyTech Spam Filtering**". Click on "**Apply this rule if** → "**The sender"** → "**IP address is in any of these ranges or exactly matches".**</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/gyMSuVo3bL5JlDBM-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/gyMSuVo3bL5JlDBM-image.png)</span>

<span style="color: rgb(0, 0, 0);">4. Specify the IP addresses in the field IP's: **35.153.237.243**(Mail Server), **107.22.65.180**(Landing Page). Please do not forget to click on "**Save**".</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/r7CiZYkeJCeTjbwE-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/r7CiZYkeJCeTjbwE-image.png)</span>

<span style="color: rgb(0, 0, 0);">5. Click the "**+**" to add another rule condition for the message headers.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/S4ggBIlJx5MjjZNX-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/S4ggBIlJx5MjjZNX-image.png)</span>

<span style="color: rgb(0, 0, 0);">6. Click on "**The message headers...."** → "**includes any of these words".**</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/mQmSmJQgc8EVK6Ft-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/mQmSmJQgc8EVK6Ft-image.png)</span>

<span style="color: rgb(0, 0, 0);">7. Click → **Enter text.**</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/E2lddVdrD882aVpr-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/E2lddVdrD882aVpr-image.png)</span>

<span style="color: rgb(0, 0, 0);">8. Specify header name → **X-PHISHTEST** and specify words or phrases **→ CYTECH.**</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/JIYvK0wFwmjjI0G9-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/JIYvK0wFwmjjI0G9-image.png)</span>

<span style="color: rgb(0, 0, 0);">9. Click the "**+**" to add another rule condition for the The sender.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/S4ggBIlJx5MjjZNX-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/S4ggBIlJx5MjjZNX-image.png)</span>

<span style="color: rgb(0, 0, 0);">10. Click on "**The sender...."** → "**domains is".** Specify the domain in your case**.** Then click **"Save".**</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/M9MlpGJUEccQSdOf-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/M9MlpGJUEccQSdOf-image.png)</span>

<span style="color: rgb(0, 0, 0);">11. Click on "**Do the following** → **Modify the message properties** → **Set a Message Header**"</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/FKdNYeHZgcr2lIs5-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/FKdNYeHZgcr2lIs5-image.png)</span>

<span style="color: rgb(0, 0, 0);">12. Click the "**Enter text**" buttons by the right side of the "**Do the following**" field and enter these values: "**MS-Exchange-Organization-BypassClutter**" and "**true**".</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/n9dPl6FKLcXOswSX-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/n9dPl6FKLcXOswSX-image.png)</span>

<span style="color: rgb(0, 0, 0);">13. Click on the "**+**" sign, to add another rule condition.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/MRkPKW5VW7yuUTso-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/MRkPKW5VW7yuUTso-image.png)</span>

<span style="color: rgb(0, 0, 0);">14. Choose "**Modify the message properties** → **Set the spam confidence level (SCL)**" and select "**Bypass Spam Filtering**", this will set the value of SCL to **-1**. Then click "**Save**" button.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/C3I64J9LDmN9k8bT-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/C3I64J9LDmN9k8bT-image.png)</span>

<span style="color: rgb(0, 0, 0);">15. Make sure you have the same output as shown in the image below before proceeding on clicking the "**Next**" button.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/bhMwvKPYIz8UpsNf-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/bhMwvKPYIz8UpsNf-image.png)</span>

<span style="color: rgb(0, 0, 0);">16. Leave the Set Rule settings as is and proceed to the Review and finish window and save the rule.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/VemlEkaeC8mYkQWO-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/VemlEkaeC8mYkQWO-image.png)</span>

<span style="color: rgb(0, 0, 0);">17. Please make sure the rule is **Enabled**, and priority is **set to "0"**. Your final Completed Mail Flow Rule screen should look as below:</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/ztnnPiUIWFeTARcW-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/ztnnPiUIWFeTARcW-image.png)</span>

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact our support at </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>