Reporting Phishing with Microsoft + Lupasafe

Lupasafe handles the phishing simulations and awareness training. For reporting suspicious emails, we deliberately use Microsoft's built-in Report button rather than a proprietary add-in.

The administrator enables this per tenant in the Microsoft Defender portal (Settings → Email & collaboration → User-reported settings): enable user reporting, select the built-in Report button, and route reported messages to a reporting mailbox that Lupasafe picks up. No separate plug-in to install.

Advantages over a proprietary button

  • No extra add-in to deploy or maintain. The Reportbutton is built into the new Outlook, Outlook Web, and Outlook Mobile by default. A platform with its own button (like Phished) requires an add-in that must be rolled out, updated, and kept compatible per tenant.
  • Future-proof. Microsoft is putting its standalone Report add-ins into maintenance mode and directing everything toward the built-in button. Building on the native button means staying aligned with that direction.
  • Double value per report. A single report simultaneously trains the Microsoft Defender filters and alerts the organization. A vendor-specific button typically routes only to that vendor's own platform.
  • One button for everything. No confusion about "which button do I press" — this lowers the barrier and increases reporting willingness.
  • Works everywhere without a separate install: desktop, web, and mobile.
  • MSP-friendly. Centrally configurable per tenant via Defender, scriptable via PowerShell/Graph and GDAP — no add-in deployment per user across all your customers.