What problem does it solve?
User-reported suspicious emails often land in unmonitored mailboxes with no triage, no remediation, and no feedback to reporters, causing security teams to miss real threats and user reporting rates to decay.
Core Features & Use Cases
- Report Button Deployment: Configure the Microsoft built-in Report button or third-party tools like KnowBe4 Phish Alert Button and Cofense Reporter across Outlook desktop, web, and mobile.
- Automated Triage Pipeline: Monitor a dedicated reporting mailbox with a SOAR platform, extract IOCs (URLs, attachments, headers), check reputation via VirusTotal and URLScan.io, and auto-classify emails as phishing, spam, simulation, or legitimate.
- Response and Feedback Loop: Auto-retract confirmed phishing from all inboxes, block sender domains, credit users for simulation reports, and send classification feedback to reporters within minutes.
- Use Case: A security team deploys the Microsoft Report button, routes submissions as .eml attachments to a reporting mailbox monitored by Microsoft Sentinel, and verifies end-to-end that a test phish triggers case creation, IOC extraction, retraction, and reporter notification.
Quick Start
Set up a phishing reporting button workflow for my Microsoft 365 environment with automated triage and reporter feedback.