Enable images in emails (Outlook Trust Center)
Usually, the automated loading of images in emails is disabled in Outlook. To make the simulated phishing emails more convincing, add two SoSafe domains as exceptions in the Outlook Trust Center.
-
Select the Spoofed senders tab and then select Add (1)
-
Add the entries in the lists (First domain pair and Second domain pair) provided below.
Note that you can only add 20 entries at a time. You must therefore split up the list into two Add/Save procedures.
-
Copy and paste the list under First domain pair, select Internal as Spoof type, and Allow as Action. Click Add to save the configuration.
Fist domain pair
*, 18.153.184.1*, 18.153.184.2*, 18.153.184.3*, 18.153.184.4*, 18.153.184.5*, 18.153.184.6*, 18.153.184.7*, 18.153.184.8*, 18.153.184.9*, 18.153.184.10*, 18.153.184.11*, 18.153.184.12*, 18.153.184.13*, 18.153.184.14*, 18.153.184.15*, 18.153.184.16*, 18.153.184.17*, 18.153.184.18*, 18.153.184.19*, 18.153.184.20
-
Copy and paste the list under Second domain pair, select Internal as Spoof type, and Allow as Action. Click Add to save the configuration.
Second domain pair
*, 18.153.184.21*, 18.153.184.22*, 18.153.184.23*, 18.153.184.24*, 18.153.184.25*, 18.153.184.26*, 18.153.184.27*, 18.153.184.28*, 18.153.184.29*, 18.153.184.30
-
Confirm that a total of 30 entries have been added to the Tenant Allow/Block Lists
Whitelisting domains with safe links (Microsoft Defender)
This articles only applies to customers with Microsoft Defender for Office 365 licensing.
By default, Microsoft Defender blocks certain elements, including SoSafe learning pages. To prevent that, certain domains used by SoSafe must be added to a policy in Microsoft Defender for Microsoft 365. Doing so only takes a few minutes, and we've prepared a step-by-step guide to make it easy for you.
-
Give the policy a name and description so you can identify it if you need to make changes in future. Select Next to continue to the Users and domains step.
-
Here, add your organization’s domain(s) in the input box titled Domains. Select Next to continue to the URL & click protection settings step.
-
Make sure the checkbox On: Safe Links checks a list of known, malicious links when users click links in email. URLs are rewritten by default is active.
-
On the same page, select Manage 0 URLs. A new dialog will open.
You will now have to add all URLs shown under List of domains used in the phishing links in the file “SoSafe Whitelisting Manual.pdf”.
Important: The format of the domain should always be like this: https://myDomain.com/*.
Example: the entry “~sosafe.de~” should be added as “https://elearning.sosafe.de/*“.
-
Select Add URLs on the Microsoft page
-
Enter the first URL shown in the file “SoSafe Whitelisting Manual.pdf”
-
Select Save, and repeat steps 1 and 2 until you have added all the URLs.