This article explains how to install and configure the SMARTFENSE phishing report button for Microsoft Outlook and Office 365, including installation requirements, notification and text configuration, and whitelist setup in Microsoft Defender.
Prerequisite: regardless of the email client used, you must validate your corporate domains in SMARTFENSE for the button to work correctly. This step is mandatory and must be completed alongside the installation.
See the guide: How to validate a domain in SMARTFENSE
To access the configuration, go to Settings > Simulations > Phishing report button. The section is organized into three tabs: Installation, Notifications, and Texts.
Installation tab
This tab allows you to obtain the button installer and configure the data required for deployment.
- Under Email client, select Outlook and Office 365.
-
Fill in the required fields:
- Tenant ID
- Application ID
- Secret
These values are obtained by following the steps in the Installation guide, available via the button of the same name in this section.
- Click Download installer to get the file corresponding to your instance.
- Complete the installation following the Button installation section of the guide.
- Click Save.
The button may take between 24 and 72 hours to appear for all users, depending on the number of accounts in the domain.
Note: the report button is not compatible with Outlook 2013 or any version no longer officially supported by Microsoft.
Notifications tab
This tab allows you to manage the email notifications generated after each report received by SMARTFENSE.
- New report alert: enable or disable notifications each time a user reports an email using the button.
- Recipients: enter the email addresses that will receive reports of external emails (not originating from simulations). If more than one address is entered, they must be comma-separated, with no spaces.
Click Save to apply changes.
Texts tab
This tab allows you to configure the messages shown to users when they use the report button in their email client.
- Use SMARTFENSE default texts: the button displays the standard messages defined by the platform.
- Use custom texts: allows you to edit the messages for each available language. Languages are selected using the flag icons in the Button texts section.
Click Save to apply changes.
Whitelist setup for the report button
The email address receiving reports must allow the following sender:
The following domains must be allowed:
- livefense.com
- phishalertbutton.com (button as of 04/20/2024)
- palertbutton.com (button prior to 04/20/2024)
And the IP address:
- 160.153.250.248
This must be configured in Microsoft Defender.
Important notes
- In Settings > Simulations > Phishing report button, click the i icon to access the online help with more details about how the button works.
- The button may take up to 72 hours to appear for all users.
- If a user has more than one account configured in Outlook, the corporate domain account must be set as the primary account for the button to appear.
Common issues
Outlook 2016 shows a compatibility error: On Office 2016 and earlier installations, Outlook depends on Internet Explorer. If it was disabled by Windows updates, the add-in may fail. Later versions require Microsoft Edge to be enabled.
Frequently asked questions about centralized deployment
SMARTFENSE recommends consulting the official Microsoft documentation:
🔗 Centralized deployment FAQ
Topics covered include: how to determine whether your organization is eligible for centralized deployment, assigning add-ins to users, and estimated deployment and removal times.
💡 Best Practices
- Validate all corporate domains before starting the installation.
- Fill in Tenant ID, Application ID, and Secret correctly to avoid installer errors.
- Set up the whitelist in Microsoft Defender before deploying the button.
- In the Notifications tab, make sure the configured recipients correspond to your organization's incident response team.
- If you want to customize the messages shown to users when reporting, use the Texts tab to tailor the language to your organization's needs.
- Verify Outlook compatibility based on the installed version.