Your company uses Microsoft 365 E5 licenses and has deployed Microsoft Defender for Office 365. The security team wants to be alerted when a user reports a phishing email using the built-in report message button in Outlook. The alert should be sent to the security team's email address. You need to configure this in the Microsoft 365 Defender portal. What should you do?
The User reported messages settings in the Microsoft 365 Defender portal (under Email & collaboration > Policies & rules > Threat policies) let you specify where messages reported by users via Outlook, Outlook on the web, or the built-in Report Message button are sent. You can direct these submissions to an internal mailbox, Microsoft, or both, and configure alert notifications so the security team is immediately informed when a user submits a message. This directly satisfies the requirement to make reports visible and actionable.
Why this answer
The correct option is B: configure the User reported messages settings to send alerts to the security team. In the Microsoft 365 Defender portal, under Email & collaboration > Policies & rules > Threat policies > User reported messages, you can specify a reporting mailbox and enable notifications so that when a user reports a phishing message via the built-in Report Message/Report Phishing add-in, the security team is alerted. This directly addresses the requirement to alert the security team when a user reports a phishing email.
Options A, C, and D do not fit: anti-phishing policies control impersonation and spoofing protections and user tips, while Safe Attachments and Safe Links policies detonate attachments and rewrite/scan URLs at delivery and click time, respectively, and none of them trigger an alert based on a user's manual report.