Skip to content
English
  • There are no suggestions because the search field is empty.

Configure Positive Phishing - Microsoft

How to configure your organisation to support a positive phishing campaign

Positive phishing is about more than just sending out simulated phishing emails; it's about creating a culture of security awareness and collaboration in schools.

When staff feel supported and educated rather than penalised, they are more likely to engage actively in cybersecurity efforts, making the school safer.

To get started, you'll need to sign in with your Microsoft Admin account. 

1. Open your Microsoft 365 admin centre and go to Integrated apps under settings. 


Screenshot 2025-09-02 at 09.47.35

2. On the integrated apps menu, select Upload custom apps

Screenshot 2025-09-02 at 10.03.11


3. When the menu pops up:

i) For App type, select Office Add-in

ii) Then choose Provide link to manifest file. Add this address: https://outlook-report-phish.secureschools.com/manifest.xml and select Validate

iii) When you see the Manifest file validated message, click Next

Screenshot 2025-09-02 at 10.10.27

4. Assign the users who should have access to the Report Phishing button in Outlook and click Next

Assign Users

5. Review the permissions Secure Schools requires access to and click next, after clicking next select finish deployment.

Screenshot 2025-09-02 at 10.49.00

6. You're good to go! As noted on the confirmation screen, it can take up to 72 hours for the app to appear for your users.

Screenshot 2025-09-02 at 10.54.50