Safelisting FortiPhish in Office 365
Perform the following steps to safelist FortiPhish in Office 365.
-
Go to https://security.microsoft.com/ and sign in using your Office 365 admin credentials.
-
In the navigation menu, select Email & collaboartion > Policies and rules.
-
Click Threat policies.
-
Select Rules > Advanced delivery.
-
In the Phishing simulation tab, if you have an existing policy for phishing simulations, click Edit. Otherwise, click Create and give the policy a name.
-
In the Add third party phishing simulations window, configure the following settings.
Domain Enter the sender's email domain specified during campaign creation in FortiPhish. See FortiPhish Administration Guide > Creating campaigns.
Sending IP Enter the IP address: 154.52.1.119 Simulation URLs Enter the custom domains specified during campaign creation. See Supported custom domains
Add the FortiPhish API endpoint IP address 34.251.104.230 to the browser safelist and to any third-party email scanners or firewalls.
-
Review your settings and click Save.
Once you have safelisted FortiPhish, simulated phishing emails should reach your users inbox without being blocked.
-
For more information on configuring Office 365 security settings, see Office 365 Security documentation.
-
For more information on FortiPhish, see FortiPhish Administration Guide.
-
Supported custom domains
For Premium Users, the following custom domain values are supported.
-
api.mytrustedpage.com
-
api.securesitepage.com
-
api.securelandingpage.com
-
api.fphpages.com
For Free Users, the following custom domain value is supported.
-
api.fphpages.com