Updates from: 05/15/2023 01:27:08
Category Microsoft Docs article Related commit history on GitHub Change details
includes Microsoft 365 Content Updates https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/includes/microsoft-365-content-updates.md
+## Week of May 08, 2023
++
+| Published On |Topic title | Change |
+|||--|
+| 5/8/2023 | [Security Operations Guide for Defender for Endpoint](/microsoft-365/security/defender-endpoint/mde-sec-ops-guide?view=o365-worldwide) | added |
+| 5/8/2023 | [Manual deployment for Microsoft Defender for Endpoint on macOS](/microsoft-365/security/defender-endpoint/mac-install-manually?view=o365-worldwide) | modified |
+| 5/8/2023 | [Set up the Microsoft Defender for Endpoint on macOS policies in Jamf Pro](/microsoft-365/security/defender-endpoint/mac-jamfpro-policies?view=o365-worldwide) | modified |
+| 5/8/2023 | [Manage automation file uploads](/microsoft-365/security/defender-endpoint/manage-automation-file-uploads?view=o365-worldwide) | modified |
+| 5/8/2023 | [Investigate users in Microsoft 365 Defender](/microsoft-365/security/defender/investigate-users?view=o365-worldwide) | modified |
+| 5/8/2023 | [Get started using Attack simulation training](/microsoft-365/security/office-365-security/attack-simulation-training-get-started?view=o365-worldwide) | modified |
+| 5/8/2023 | [Manage quarantined messages and files as an admin](/microsoft-365/security/office-365-security/quarantine-admin-manage-messages-files?view=o365-worldwide) | modified |
+| 5/8/2023 | [Administration guide for Microsoft 365 Business Premium](/microsoft-365/business-premium/m365bp-admin-guide?view=o365-worldwide) | added |
+| 5/8/2023 | [Security operations guide for Microsoft 365 Business Premium](/microsoft-365/business-premium/m365bp-security-operations-guide?view=o365-worldwide) | added |
+| 5/8/2023 | Add a new user to your network and systems | removed |
+| 5/8/2023 | [Maintain your environment](/microsoft-365/business-premium/m365bp-maintain-environment?view=o365-worldwide) | modified |
+| 5/8/2023 | [Secure managed and unmanaged devices](/microsoft-365/business-premium/m365bp-managed-unmanaged-devices?view=o365-worldwide) | modified |
+| 5/8/2023 | Remove company data from devices | removed |
+| 5/8/2023 | Reset Windows devices to their factory settings | removed |
+| 5/8/2023 | Reset passwords | removed |
+| 5/8/2023 | Security operations guide for Microsoft 365 Business Premium | removed |
+| 5/8/2023 | [Microsoft Purview Compliance Manager regulations list](/microsoft-365/compliance/compliance-manager-templates-list?view=o365-worldwide) | modified |
+| 5/8/2023 | Security Operations Guide for Defender for Endpoint | removed |
+| 5/9/2023 | [Security administration guide for Microsoft 365 Business Premium](/microsoft-365/business-premium/m365bp-security-admin-guide?view=o365-worldwide) | added |
+| 5/9/2023 | [Document compliance with Microsoft Syntex](/microsoft-365/syntex/scenario-document-compliance) | added |
+| 5/9/2023 | [Find content details with Microsoft Syntex](/microsoft-365/syntex/scenario-find-content-details) | added |
+| 5/9/2023 | [Generate documents in bulk with Microsoft Syntex](/microsoft-365/syntex/scenario-generate-documents-bulk) | added |
+| 5/9/2023 | [Automatically generate routine documents with Microsoft Syntex](/microsoft-365/syntex/scenario-generate-routine-documents) | added |
+| 5/9/2023 | [Handle incoming documents with Microsoft Syntex](/microsoft-365/syntex/scenario-handle-incoming-documents) | added |
+| 5/9/2023 | [Make information easier to find with Microsoft Syntex](/microsoft-365/syntex/scenario-organize-repositories) | added |
+| 5/9/2023 | [Get started with Endpoint data loss prevention](/microsoft-365/compliance/endpoint-dlp-getting-started?view=o365-worldwide) | modified |
+| 5/9/2023 | [Get started with insider risk management](/microsoft-365/compliance/insider-risk-management-configure?view=o365-worldwide) | modified |
+| 5/9/2023 | [Create and manage insider risk management policies](/microsoft-365/compliance/insider-risk-management-policies?view=o365-worldwide) | modified |
+| 5/9/2023 | [Get started with insider risk management settings](/microsoft-365/compliance/insider-risk-management-settings?view=o365-worldwide) | modified |
+| 5/9/2023 | [Investigate alerts in Microsoft 365 Defender](/microsoft-365/security/defender/investigate-alerts?view=o365-worldwide) | modified |
+| 5/9/2023 | [Scenarios and use cases for Microsoft Syntex](/microsoft-365/syntex/adoption-scenarios) | modified |
+| 5/9/2023 | [Protect against malware and other threats with Microsoft 365 Business Premium](/microsoft-365/business-premium/m365bp-protect-against-malware-cyberthreats?view=o365-worldwide) | modified |
+| 5/9/2023 | [Boost your security protection with Microsoft 365 Business Premium](/microsoft-365/business-premium/m365bp-security-overview?view=o365-worldwide) | modified |
+| 5/9/2023 | [Top 10 ways to secure your business data with Microsoft 365 for business](/microsoft-365/business-premium/secure-your-business-data?view=o365-worldwide) | modified |
+| 5/10/2023 | [Set up Microsoft 365 Business Premium](/microsoft-365/business-premium/m365-business-premium-setup?view=o365-worldwide) | renamed |
+| 5/10/2023 | Sign up for Microsoft 365 Business Premium | removed |
+| 5/10/2023 | Get Microsoft 365 for Campaigns | removed |
+| 5/10/2023 | [Microsoft 365 Business Premium overview](/microsoft-365/business-premium/index?view=o365-worldwide) | modified |
+| 5/10/2023 | [Setup overview for Microsoft 365 for Campaigns](/microsoft-365/business-premium/m365-campaigns-setup?view=o365-worldwide) | modified |
+| 5/10/2023 | [Why choose Microsoft 365 Business Premium? Productivity and security](/microsoft-365/business-premium/why-choose-microsoft-365-business-premium?view=o365-worldwide) | modified |
+| 5/10/2023 | [Get started with Endpoint data loss prevention](/microsoft-365/compliance/endpoint-dlp-getting-started?view=o365-worldwide) | modified |
+| 5/10/2023 | [Microsoft 365 documentation # < 60 chars](/microsoft-365/index?view=o365-worldwide) | modified |
+| 5/10/2023 | [Set up Microsoft 365 Business Premium](/microsoft-365/business-premium/m365-business-premium-setup?view=o365-worldwide) | modified |
+| 5/10/2023 | Get Microsoft Defender for Business servers | removed |
+| 5/10/2023 | [Get Microsoft Defender for Business](/microsoft-365/security/defender-business/get-defender-business?view=o365-worldwide) | modified |
+| 5/10/2023 | [Microsoft Defender for Business frequently asked questions](/microsoft-365/security/defender-business/mdb-faq?view=o365-worldwide) | modified |
+| 5/10/2023 | [Manage devices in Microsoft Defender for Business](/microsoft-365/security/defender-business/mdb-manage-devices?view=o365-worldwide) | modified |
+| 5/10/2023 | [Manage exclusions for Microsoft Defender for Endpoint and Microsoft Defender Antivirus](/microsoft-365/security/defender-endpoint/defender-endpoint-antivirus-exclusions?view=o365-worldwide) | modified |
+| 5/10/2023 | Recover from a ransomware attack | removed |
+| 5/11/2023 | [Audit log activities](/microsoft-365/compliance/audit-log-activities?view=o365-worldwide) | modified |
+| 5/11/2023 | [Search the audit log in the Microsoft Purview compliance portal](/microsoft-365/compliance/audit-log-search?view=o365-worldwide) | modified |
+| 5/11/2023 | [Search for and delete chat messages in Teams](/microsoft-365/compliance/ediscovery-search-and-delete-teams-chat-messages?view=o365-worldwide) | modified |
+| 5/11/2023 | [View Defender for Office 365 reports](/microsoft-365/security/office-365-security/reports-defender-for-office-365?view=o365-worldwide) | modified |
+| 5/11/2023 | [View email security reports](/microsoft-365/security/office-365-security/reports-email-security?view=o365-worldwide) | modified |
+| 5/11/2023 | [Malaysia passport number entity definition](/microsoft-365/compliance/sit-defn-malaysia-passport-number?view=o365-worldwide) | added |
+| 5/11/2023 | [Singapore driver's license number entity definition](/microsoft-365/compliance/sit-defn-singapore-drivers-license-number?view=o365-worldwide) | added |
+| 5/11/2023 | [Singapore passport number entity definition](/microsoft-365/compliance/sit-defn-singapore-passport-number?view=o365-worldwide) | added |
+| 5/11/2023 | [South Korea driver's license number entity definition](/microsoft-365/compliance/sit-defn-south-korea-drivers-license-number?view=o365-worldwide) | added |
+| 5/11/2023 | [South Korea passport number entity definition](/microsoft-365/compliance/sit-defn-south-korea-passport-number?view=o365-worldwide) | added |
+| 5/11/2023 | [UAE identity card number entity definition](/microsoft-365/compliance/sit-defn-uae-identity-card-number?view=o365-worldwide) | added |
+| 5/11/2023 | [UAE passport number entity definition](/microsoft-365/compliance/sit-defn-uae-passport-number?view=o365-worldwide) | added |
+| 5/11/2023 | [Data Residency Legacy Move Program](/microsoft-365/enterprise/m365-dr-legacy-move-program?view=o365-worldwide) | modified |
+| 5/11/2023 | [Overview and Definitions](/microsoft-365/enterprise/m365-dr-overview?view=o365-worldwide) | modified |
+| 5/11/2023 | [Microsoft Defender for Endpoint Device Control Removable Storage frequently asked questions](/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control-faq?view=o365-worldwide) | modified |
+| 5/12/2023 | [Restore a deleted Microsoft 365 group](/microsoft-365/admin/create-groups/restore-deleted-group?view=o365-worldwide) | modified |
+| 5/12/2023 | [Configure endpoint DLP settings](/microsoft-365/compliance/dlp-configure-endpoint-settings?view=o365-worldwide) | modified |
+| 5/12/2023 | [Malaysia passport number entity definition](/microsoft-365/compliance/sit-defn-malaysia-passport-number?view=o365-worldwide) | modified |
+| 5/12/2023 | [Singapore passport number entity definition](/microsoft-365/compliance/sit-defn-singapore-passport-number?view=o365-worldwide) | modified |
+| 5/12/2023 | [South Korea driver's license number entity definition](/microsoft-365/compliance/sit-defn-south-korea-drivers-license-number?view=o365-worldwide) | modified |
+| 5/12/2023 | [South Korea passport number entity definition](/microsoft-365/compliance/sit-defn-south-korea-passport-number?view=o365-worldwide) | modified |
+| 5/12/2023 | [UAE identity card number entity definition](/microsoft-365/compliance/sit-defn-uae-identity-card-number?view=o365-worldwide) | modified |
+| 5/12/2023 | [UAE passport number entity definition](/microsoft-365/compliance/sit-defn-uae-passport-number?view=o365-worldwide) | modified |
+| 5/12/2023 | [Create and publish sensitivity labels](/microsoft-365/compliance/create-sensitivity-labels?view=o365-worldwide) | modified |
+| 5/12/2023 | [Impersonation insight](/microsoft-365/security/office-365-security/anti-phishing-mdo-impersonation-insight?view=o365-worldwide) | modified |
+| 5/12/2023 | [Configure anti-phishing policies in Microsoft Defender for Office 365](/microsoft-365/security/office-365-security/anti-phishing-policies-mdo-configure?view=o365-worldwide) | modified |
++ ## Week of May 01, 2023
| 4/14/2023 | [Secure managed and unmanaged devices](/microsoft-365/business-premium/m365bp-managed-unmanaged-devices?view=o365-worldwide) | added | | 4/14/2023 | [Set up unmanaged devices overview](/microsoft-365/business-premium/m365bp-devices-overview?view=o365-worldwide) | modified | | 4/14/2023 | [Protect unmanaged Windows PCs and Macs in Microsoft 365 Business Premium](/microsoft-365/business-premium/m365bp-protect-pcs-macs?view=o365-worldwide) | modified |--
-## Week of April 03, 2023
--
-| Published On |Topic title | Change |
-|||--|
-| 4/3/2023 | [Endpoint detection and response (EDR) in block mode frequently asked questions (FAQ)](/microsoft-365/security/defender-endpoint/edr-block-mode-faqs?view=o365-worldwide) | added |
-| 4/3/2023 | [Endpoint detection and response in block mode](/microsoft-365/security/defender-endpoint/edr-in-block-mode?view=o365-worldwide) | modified |
-| 4/3/2023 | [macOS Device control policies frequently asked questions (FAQ)](/microsoft-365/security/defender-endpoint/mac-device-control-faq?view=o365-worldwide) | added |
-| 4/3/2023 | [Deploy and manage Device Control using Intune](/microsoft-365/security/defender-endpoint/mac-device-control-intune?view=o365-worldwide) | modified |
-| 4/3/2023 | [Deploy and manage device control using JAMF](/microsoft-365/security/defender-endpoint/mac-device-control-jamf?view=o365-worldwide) | modified |
-| 4/3/2023 | [Device control for macOS](/microsoft-365/security/defender-endpoint/mac-device-control-overview?view=o365-worldwide) | modified |
-| 4/3/2023 | [Errors during admin submissions](/microsoft-365/security/office-365-security/submissions-error-messages?view=o365-worldwide) | modified |
-| 4/3/2023 | [Allow or block URLs using the Tenant Allow/Block List](/microsoft-365/security/office-365-security/tenant-allow-block-list-urls-configure?view=o365-worldwide) | modified |
-| 4/3/2023 | [Overview of Copilot for Microsoft Syntex](/microsoft-365/syntex/syntex-copilot) | modified |
-| 4/3/2023 | [Pay for your Microsoft business subscription with a billing profile](/microsoft-365/commerce/billing-and-payments/pay-for-subscription-billing-profile?view=o365-worldwide) | modified |
-| 4/3/2023 | [Payment options for your Microsoft business subscription](/microsoft-365/commerce/billing-and-payments/pay-for-your-subscription?view=o365-worldwide) | modified |
-| 4/3/2023 | [Understand your bill or invoice for Microsoft 365 for business](/microsoft-365/commerce/billing-and-payments/understand-your-invoice2?view=o365-worldwide) | modified |
-| 4/3/2023 | [Security baselines assessment](/microsoft-365/security/defender-vulnerability-management/tvm-security-baselines?view=o365-worldwide) | modified |
-| 4/3/2023 | [Get started with Endpoint data loss prevention](/microsoft-365/compliance/endpoint-dlp-getting-started?view=o365-worldwide) | modified |
-| 4/3/2023 | [Tailor Teams apps for your frontline workers](/microsoft-365/frontline/pin-teams-apps-based-on-license?view=o365-worldwide) | modified |
-| 4/3/2023 | [What's new in Microsoft 365 Lighthouse](/microsoft-365/lighthouse/m365-lighthouse-whats-new?view=o365-worldwide) | modified |
-| 4/5/2023 | [Setup guides for Microsoft 365 Defender](/microsoft-365/security/defender/deploy-configure-m365-defender?view=o365-worldwide) | added |
-| 4/5/2023 | [Use Content Search in Microsoft Teams](/microsoft-365/compliance/ediscovery-teams-content-search?view=o365-worldwide) | added |
-| 4/5/2023 | [Place a Microsoft Teams user or team on legal hold](/microsoft-365/compliance/ediscovery-teams-legal-hold?view=o365-worldwide) | added |
-| 4/5/2023 | [Conduct an eDiscovery investigation of content in Microsoft Teams](/microsoft-365/compliance/ediscovery-teams-investigation?view=o365-worldwide) | modified |
-| 4/5/2023 | [eDiscovery (Premium) workflow for content in Microsoft Teams](/microsoft-365/compliance/ediscovery-teams-workflow?view=o365-worldwide) | modified |
-| 4/5/2023 | [Minimum versions for sensitivity labels in Microsoft 365 Apps](/microsoft-365/compliance/sensitivity-labels-versions?view=o365-worldwide) | modified |
-| 4/6/2023 | [Use Content Search in Microsoft Teams](/microsoft-365/compliance/ediscovery-teams-content-search?view=o365-worldwide) | modified |
-| 4/6/2023 | [Place a Microsoft Teams user or team on legal hold](/microsoft-365/compliance/ediscovery-teams-legal-hold?view=o365-worldwide) | modified |
-| 4/6/2023 | Frequently asked questions on tamper protection | removed |
-| 4/7/2023 | [Upgrade your Office 2010 to Microsoft 365 - Microsoft 365 admin](/microsoft-365/admin/setup/upgrade-users-to-latest-office-client?view=o365-worldwide) | modified |
-| 4/7/2023 | [Virtual Appointments with Teams - Integration into Epic EHR](/microsoft-365/frontline/ehr-admin-epic?view=o365-worldwide) | modified |
-| 4/7/2023 | [Configure anti-malware policies](/microsoft-365/security/office-365-security/anti-malware-policies-configure?view=o365-worldwide) | modified |
-| 4/7/2023 | [Configure anti-phishing policies in EOP](/microsoft-365/security/office-365-security/anti-phishing-policies-eop-configure?view=o365-worldwide) | modified |
-| 4/7/2023 | [Configure anti-phishing policies in Microsoft Defender for Office 365](/microsoft-365/security/office-365-security/anti-phishing-policies-mdo-configure?view=o365-worldwide) | modified |
-| 4/7/2023 | [Configure spam filter policies](/microsoft-365/security/office-365-security/anti-spam-policies-configure?view=o365-worldwide) | modified |
-| 4/7/2023 | [Protect against threats in Microsoft Defender for Office 365, Anti-malware, Anti-Phishing, Anti-spam, Safe links, Safe attachments, Zero-hour auto purge (ZAP), MDO security configuration](/microsoft-365/security/office-365-security/protect-against-threats?view=o365-worldwide) | modified |
-| 4/7/2023 | [Quarantined messages FAQ](/microsoft-365/security/office-365-security/quarantine-faq?view=o365-worldwide) | modified |
-| 4/7/2023 | [Quarantine policies](/microsoft-365/security/office-365-security/quarantine-policies?view=o365-worldwide) | modified |
-| 4/7/2023 | [Quarantine notifications (end-user spam notifications) in Microsoft 365](/microsoft-365/security/office-365-security/quarantine-quarantine-notifications?view=o365-worldwide) | modified |
-| 4/7/2023 | [Microsoft recommendations for EOP and Defender for Office 365 security settings](/microsoft-365/security/office-365-security/recommended-settings-for-eop-and-office365?view=o365-worldwide) | modified |
-| 4/7/2023 | [Set up Safe Attachments policies in Microsoft Defender for Office 365](/microsoft-365/security/office-365-security/safe-attachments-policies-configure?view=o365-worldwide) | modified |
-| 4/7/2023 | [Zero-hour auto purge in Microsoft Defender for Office 365](/microsoft-365/security/office-365-security/zero-hour-auto-purge?view=o365-worldwide) | modified |
-| 4/7/2023 | [Overview of the Tenants page in Microsoft 365 Lighthouse](/microsoft-365/lighthouse/m365-lighthouse-tenants-page-overview?view=o365-worldwide) | modified |
security Windows Whatsnew https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/windows-whatsnew.md
ms.pagetype: security
ms.localizationpriority: medium Previously updated : 01/25/2023 Last updated : 05/14/2023 audience: ITPro
All updates contain:
- Serviceability improvements - Integration improvements (Cloud, [Microsoft 365 Defender](https://go.microsoft.com/fwlink/?linkid=2118804))
+## May-2023 (Release version: 10.8295.22621.1023)
+
+|OS |KB |Release version |
+||||
+|Windows Server 2012 R2, 2016 |[KB 5005292](https://support.microsoft.com/en-us/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8295.22621.1023|
+
+**What's new**
+
+- Supports new security settings management capabilities
## Jan/Feb-2023 (Release version: 10.8295.22621.1019)
security Configuration Analyzer For Security Policies https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/configuration-analyzer-for-security-policies.md
The Standard and Strict policy setting values that are used as baselines are des
- _Use the configuration analyzer and update the affected security policies_: Membership in the **Organization Management** or **Security Administrator** role groups. - _Read-only access to the configuration analyzer_: Membership in the **Global Reader** or **Security Reader** role groups. - [Exchange Online RBAC](/Exchange/permissions-exo/permissions-exo): Membership in the **View-Only Organization Management** role group gives read-only access to the configuration analyzer.
- - [Azure AD RBAC](../../admin/add-users/about-admin-roles.md): Membership in the **Global Administrator**, **Security Administrator**, **Global Reader**, or **Security Reader** roles gies users the required permissions _and_ permissions for other features in Microsoft 365.
+ - [Azure AD RBAC](../../admin/add-users/about-admin-roles.md): Membership in the **Global Administrator**, **Security Administrator**, **Global Reader**, or **Security Reader** roles gives users the required permissions _and_ permissions for other features in Microsoft 365.
## Use the configuration analyzer in the Microsoft 365 Defender portal
security Submissions Users Report Message Add In Configure https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/submissions-users-report-message-add-in-configure.md
audience: Admin Previously updated : 12/15/2022 Last updated : 5/12/2023 ms.localizationpriority: medium search.appverid: - MET150
> [!NOTE] > If you're an admin in a Microsoft 365 organization with Exchange Online mailboxes, we recommend that you use the **Submissions** page in the Microsoft 365 Defender portal. For more information, see [Use Admin Submission to submit suspected spam, phish, URLs, and files to Microsoft](submissions-admin.md).
-The Microsoft Report Message and Report Phishing add-ins for Outlook and Outlook on the web (formerly known as Outlook Web App or OWA) makes it easy to report false positives (good email marked as bad) or false negatives (bad email allowed) to Microsoft and its affiliates for analysis.
+The Microsoft Report Message and Report Phishing add-ins for Outlook and Outlook on the web (formerly known as Outlook Web App or OWA) makes it easy for users to report false positives and false negatives to Microsoft for analysis. False positives are good email that was blocked or sent to the Junk Email folder. False negatives are unwanted email or phishing that was delivered to the Inbox.
Microsoft uses these user reported messages to improve the effectiveness of email protection technologies. For example, suppose that people are reporting many messages using the Report Phishing add-in. This information surfaces in the Security Dashboard and other reports. Your organization's security team can use this information as an indication that anti-phishing policies might need to be updated.
-You can install either the Report Message or the Report Phishing add-in. If you want your users to report both spam and phishing messages, deploy the Report Message add-in in your organization.
+The Report Message add-in provides the option to report both spam and phishing messages. The Report Phishing add-in provides the option to report phishing messages only.
-The Report Message add-in provides the option to report both spam and phishing messages. Admins can enable the Report Message add-in for the organization, and individual users can install it for themselves.
+Admins can install and enable the add-ins for the organization. Both add-ins are available through [Centralized Deployment](../../admin/manage/centralized-deployment-of-add-ins.md). Individual users can install the add-ins for themselves.
-The Report Phishing add-in provides the option to report only phishing messages. Admins can enable the Report Phishing add-in for the organization, and individual users can install it for themselves.
-
-If you're an individual user, you can enable both the add-ins for yourself.
-
-If you're a global administrator or an Exchange Online administrator, and Exchange is configured to use OAuth authentication, you can enable the Report Message and Report Phishing add-ins for your organization. Both add-ins are now available through [Centralized Deployment](../../admin/manage/centralized-deployment-of-add-ins.md).
-
-After the add-in is installed and enabled, users will see the following icons:
+After the add-in is installed and enabled, users see the following icons based on their Outlook client:
- **Outlook for Windows**:
- - The **Report Message** icon in the Classic Ribbon:
+ - <u>The **Report Message** icon in the Classic Ribbon</u>:
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/OutlookReportMessageIcon.png" alt-text="The Report Message add-in using the Classic Ribbon in Outlook." lightbox="../../media/OutlookReportMessageIcon.png":::
- - The **Report Message** icon in the Simplified Ribbon: Click ![More commands icon.](../../media/m365-cc-sc-more-actions-icon.png) **More commands** \> **Protection** section \> **Report Message**.
+ - <u>The **Report Message** icon in the Simplified Ribbon</u>: Select :::image type="icon" source="../../media/m365-cc-sc-more-actions-icon.png" border="false"::: **More commands** \> **Report Message** in the **Protection** section.
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/OutlookReportMessage-simplified.png" alt-text="The Report Message add-in using the Simplified Ribbon in Outlook." lightbox="../../media/OutlookReportMessage-simplified.png":::
- - The **Report Phishing** icon in the Classic Ribbon:
+ - <u>The **Report Phishing** icon in the Classic Ribbon</u>:
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/Outlook-ReportPhishing.png" alt-text="The Report Phishing add-in in Outlook." lightbox="../../media/Outlook-ReportPhishing.png":::
- - The **Report Phishing** icon in the Simplified Ribbon: Click ![More commands icon.](../../media/m365-cc-sc-more-actions-icon.png) **More commands** \> **Protection** section \> **Report Phishing**.
+ - <u>The **Report Phishing** icon in the Simplified Ribbon</u>: Select :::image type="icon" source="../../media/m365-cc-sc-more-actions-icon.png" border="false"::: **More commands** \> **Report phishing** in the **Protection** section.
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/Outlook-ReportPhishing-simplified.png" alt-text="The Report Phishing add-in using the Simplified Ribbon in Outlook." lightbox="../../media/Outlook-ReportPhishing-simplified.png"::: - **Outlook on the web**:
- - The Report Message add-in:
+ - <u>The Report Message add-in</u>:
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/owa-report-message-icon.png" alt-text="The Report Message add-in icon in Outlook on the web." lightbox="../../media/owa-report-message-icon.png":::
- - The Report Phishing add-in:
+ - <u>The Report Phishing add-in</u>:
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/OWA-ReportPhishing.png" alt-text="The Report Phishing add-in icon in Outlook on the web." lightbox="../../media/OWA-ReportPhishing.png"::: ## What do you need to know before you begin?
+- You need to be assigned permissions before you can do the procedures in this article. You have the following options:
+ - [Email & collaboration RBAC in the Microsoft 365 Defender portal](mdo-portal-permissions.md): Membership in the **Organization Management** role group.
+ - [Exchange Online RBAC](/Exchange/permissions-exo/permissions-exo): Membership in the **Organization Management** role group.
+ - [Azure AD RBAC](../../admin/add-users/about-admin-roles.md): Membership in the **Global Administrator** role gives users the required permissions _and_ permissions for other features in Microsoft 365.
+
+- For organizational installs, the organization needs to be configured to use OAuth authentication. For more information, see [Determine if Centralized Deployment of add-ins works for your organization](../../admin/manage/centralized-deployment-of-add-ins.md).
+ - The Report Message and Report Phishing add-ins work with most Microsoft 365 subscriptions and the following products: - Outlook on the web - Outlook 2013 SP1 or later
After the add-in is installed and enabled, users will see the following icons:
- Outlook included with Microsoft 365 apps for Enterprise - Outlook for iOS and Android -- The add-ins are not available for shared, group, or delegated mailboxes (**Report message** will be greyed out).--- The add-ins are not available for on-premises Exchange mailboxes.--- Your existing web browser should work with the Report Message and Report Phishing add-ins. But, if you notice an add-in isn't available or not working as expected, try a different browser.--- For organizational installs, the organization needs to be configured to use OAuth authentication. For more information, see [Determine if Centralized Deployment of add-ins works for your organization](../../admin/manage/centralized-deployment-of-add-ins.md).
+- Currently, reporting messages in shared mailboxes or other mailboxes by a delegate using the add-ins isn't supported. Messages aren't sent to the [reporting mailbox](submissions-user-reported-messages-custom-mailbox.md) or to Microsoft. Built-in reporting in Outlook on the web in shared mailboxes or other mailboxes by a delegate is supported. Messages are sent to the reporting mailbox or to Microsoft.
-- Admins need to be a member of the Global admins role group. For more information, see [Permissions in the Microsoft 365 Defender portal](mdo-portal-permissions.md).
+- The add-ins aren't available for on-premises Exchange mailboxes.
- For more information on how to report a message using the Report Message feature, see [Report false positives and false negatives in Outlook](submissions-outlook-report-messages.md). -- Organizations that have a URL filtering or security solution (such as a proxy and/or firewall) in place, must have ipagave.azurewebsites.net and outlook.office.com endpoints allowed to be reached on HTTPS protocol.--- Currently, reporting messages in shared mailboxes or other mailboxes by a delegate using the add-ins is not supported. Messages are not sent to the [reporting mailbox](submissions-user-reported-messages-custom-mailbox.md) or to Microsoft. Built-in reporting in Outlook on the web sends messages reported by a delegate to the reporting mailbox and/or to Microsoft.
+ > [!NOTE]
+ > Reported messages are available to admins on the **User reported** tab of **Submissions** page at <https://security.microsoft.com/reportsubmission?viewid=user> **only** if both of the following settings are configured on the **User reported** page at <https://security.microsoft.com/securitysettings/userSubmission>:
+ >
+ > - The toggle on the **User reported** page is **On** :::image type="icon" source="../../media/scc-toggle-on.png" border="false":::.
+ > - **Use the built-in "Report" button with "Phishing", "Junk", and "Not Junk options"** is selected.
-> [!IMPORTANT]
-> Admins can view reported messages on the **Submissions** page at <https://security.microsoft.com/reportsubmission> **only** if both of the following settings are configured on the **User reported** page at <https://security.microsoft.com/securitysettings/userSubmission>:
->
-> - The toggle on the **User reported** page is **On** ![Toggle on.](../../media/scc-toggle-on.png).
-> - **Use the built-in "Report" button with "Phishing", "Junk", and "Not Junk options"** is selected.
-
-## Use the built-in Report button in Outlook on the web
+- Organizations that use URL filtering or a third-party security solutions (for example, a proxy and/or firewall) must be able to reach the following URLs using the HTTPS protocol:
+ - `ipagave.azurewebsites.net`
+ - `outlook.office.com`
## Admin instructions
Install and configure the Report Message or Report Phishing add-ins for the orga
> [!NOTE] > It could take up to 12 hours for the add-in to appear in your organization.
+>
+> When you follow these instructions to centrally deploy the add-ins, a corresponding app registration is also deployed in Azure. If you delete the app registration for the add-in in Azure, the add-in is also deleted from the organization.
### Get the Report Message or Report Phishing add-in for your organization 1. In the Microsoft 365 admin center at <https://admin.microsoft.com>, expand **Show all** if necessary, and then go to **Settings** \> **Integrated apps**. Or, to go directly to the **Integrated apps** page, use <https://admin.microsoft.com/Adminportal/Home#/Settings/IntegratedApps>.
-2. On the **Integrated apps** page, click ![Get apps icon.](../../media/m365-cc-sc-get-apps-icon.png)**Get apps**.
+2. On the **Integrated apps** page, select :::image type="icon" source="../../media/m365-cc-sc-get-apps-icon.png" border="false"::: **Get apps**.
> [!div class="mx-imgBorder"]
- > :::image type="content" source="../../media/microsoft-365-admin-center-integrated-apps.png" alt-text="The Integrated apps page in the Microsoft 365 admin center where you click Get apps." lightbox="../../media/microsoft-365-admin-center-integrated-apps.png":::
+ > :::image type="content" source="../../media/microsoft-365-admin-center-integrated-apps.png" alt-text="The Integrated apps page in the Microsoft 365 admin center where you select Get apps." lightbox="../../media/microsoft-365-admin-center-integrated-apps.png":::
-3. In the **Microsoft 365 Apps** page that opens, enter **Report Message** in the ![Search icon.](../../media/search-icon.png) **Search** box.
+3. In the **Microsoft 365 Apps** page that opens, enter **Report Message** in the :::image type="icon" source="../../media/m365-cc-sc-search-icon.png" border="false"::: **Search** box.
- In the search results, click **Get it now** in the **Report Message** entry or the **Report Phishing** entry.
+ In the search results, select **Get it now** in the **Report Message** entry or the **Report Phishing** entry to start the **Deploy New App** wizard.
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/microsoft-365-admin-center-report-message.png" alt-text="Search results for Report Message showing the Report Message and Report Phishing add-ins, and the Get it now buttons on each." lightbox="../../media/microsoft-365-admin-center-report-message.png":::
Install and configure the Report Message or Report Phishing add-ins for the orga
> [!NOTE] > Although the screenshots in the remaining steps show the **Report Message** add-in, the steps are identical for the **Report Phishing** add-in.
-4. The **Deploy New App** wizard opens. On the **Add users** page, configure the following settings:
+4. On the **Add users** page, configure the following settings:
- - **Is this a test deployment?**: Leave the toggle at ![Toggle off.](../../media/scc-toggle-off.png) **No**, or set the toggle to ![Toggle on.](../../media/scc-toggle-on.png) **Yes**.
+ - **Is this a test deployment?**: Leave the toggle at :::image type="icon" source="../../media/scc-toggle-off.png" border="false"::: **No**, or set the toggle to :::image type="icon" source="../../media/scc-toggle-on.png" border="false"::: **Yes**.
- **Assign users**: Select one of the following values: - **Just me** - **Entire organization**
- - **Specific users/groups**: Find and select users and groups in the search box. After each selection, the user or group appears in the **To be added** section that appears below the search box. To remove a selection, click ![Remove entry icon.](../../media/m365-cc-sc-remove-selection-icon.png) on the entry.
+ - **Specific users/groups**: Find and select users and groups in the search box. After each selection, the user or group appears in the **To be added** section that appears below the search box. To remove a selection, select :::image type="icon" source="../../media/m365-cc-sc-remove-selection-icon.png" border="false"::: on the entry.
- - **Email notification**: By default the **Send email notification to assigned users** is selected. Click **View email sample** to open the Add-in deployment email alerts](/microsoft-365/admin/manage/add-in-deployment-email-alerts) article.
+ - **Email notification**: By default, **Send email notification to assigned users** is selected. Select **View email sample** to open the [Add-in deployment email alerts](/microsoft-365/admin/manage/add-in-deployment-email-alerts) article.
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/microsoft-365-admin-center-deploy-new-app-add-users.png" alt-text="The Add users page of Deploy New App." lightbox="../../media/microsoft-365-admin-center-deploy-new-app-add-users.png":::
- When you're finished, click **Next**.
+ When you're finished on the **Add users** page, select **Next**.
-5. On the **Accept permissions requests** page, read the app permissions and capabilities information carefully before you click **Next**.
+5. On the **Accept permissions requests** page, read the app permissions and capabilities information carefully before you select **Next**.
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/microsoft-365-admin-center-deploy-new-app-accept-permissions-requests.png" alt-text="The Accept permissions requests page of Deploy New App." lightbox="../../media/microsoft-365-admin-center-deploy-new-app-accept-permissions-requests.png":::
-6. On the **Review and finish deployment** page, review your settings. Click **Back** to make changes.
+6. On the **Review and finish deployment** page, review your settings. Select **Back** to make changes.
- When you're finished, click **Finish deployment**.
+ When you're finished on the **Review and finish deployment** page, select **Finish deployment**.
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/microsoft-365-admin-center-deploy-new-app-review-and-finish.png" alt-text="The Review and finish deployment page of Deploy New App." lightbox="../../media/microsoft-365-admin-center-deploy-new-app-review-and-finish.png":::
-7. A progress indicator appears on the **Review and finish deployment** page. If deployment of the add-in is successful, the page title changes to **Deployment completed**.
+ A progress indicator appears on the **Review and finish deployment** page.
+
+7. On the **Deployment completed page**, you can select **view this deployment** to close the page and go to [the details of the add-in](#view-and-edit-settings-for-the-report-message-or-report-phishing-add-ins). Or, select **Done** to close the page.
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/microsoft-365-admin-center-deployment-complete.png" alt-text="The notification message of the deployment completed." lightbox="../../media/microsoft-365-admin-center-deployment-complete.png":::
- When you're finished, click **Done**.
-
- If you click **View this deployment**, the page closes and you're taken to the details of the add-in as described in the next section.
- ### Get the Report Message or the Report Phishing add-ins for your Microsoft 365 GCC or GCC High organization Admins in Microsoft 365 Government Community Cloud (GCC) or GCC High need to use the steps in this section to get the Report Message or Report Phishing add-ins for their organizations.
Admins in Microsoft 365 Government Community Cloud (GCC) or GCC High need to use
> [!NOTE] > It could take up to 24 hours for the add-in to appear in your organization. >
-> In U.S. Government organizations (Microsoft 365 GCC, GCC High, and DoD), reported messages are not sent to Microsoft for analysis. They are sent only to the reporting mailbox that you identify. For more information, see [User reported settings](submissions-user-reported-messages-custom-mailbox.md).
-
-1. In the Microsoft 365 admin center at <https://portal.office365.us/adminportal/home#/Settings/AddIns> open settings by selecting **Settings**.
+> In U.S. Government organizations (Microsoft 365 GCC, GCC High, and DoD), reported messages aren't sent to Microsoft for analysis. They are sent only to the reporting mailbox that you identify. For more information, see [User reported settings](submissions-user-reported-messages-custom-mailbox.md).
-2. On the settings page, select the **Add-ins** option. Then select **Deploy Add-in** followed by **upload custom apps**
+1. In the Microsoft 365 admin center at <https://portal.office365.us/adminportal/home#/Settings/AddIns>, select **Settings** \> **Add-ins** \> **Deploy Add-in** \> **Upload custom apps**.
-3. On the upload custom apps side panel, select **I have a URL for the manifest file**.
+2. In the **Upload custom apps** flyout that opens, select **I have a URL for the manifest file**.
4. In the **Add from URL** dialog that opens, enter one of the following URLs: - **Report Message**: <https://ipagave.azurewebsites.net/ReportMessageManifest/ReportMessageAzure.xml> - **Report Phishing**: <https://ipagave.azurewebsites.net/ReportPhishingManifest/ReportPhishingAzure.xml>
- When you're finished, click **Install**. In the success dialog, click **OK**.
+ When you're finished, select **Install**. In the success dialog, select **OK**.
-5. Back on the **Add-ins** page, select the add-in you just installed, and then click ![Edit icon.](../../media/ITPro-EAC-EditIcon.png) **Edit**.
+5. Back on the **Add-ins** page, select the add-in you installed, and then select :::image type="icon" source="../../media/m365-cc-sc-edit-icon.png" border="false"::: **Edit**.
6. In the add-in properties dialog that opens, confirm or modify the following settings: - **Make this add-in available to users in your organization**.
Admins in Microsoft 365 Government Community Cloud (GCC) or GCC High need to use
- **Optional, disabled by default**. - **Mandatory, always enabled. Users can't disable this add-in**.
- When you're finished, click **Save**.
+ When you're finished, select **Save**.
7. To fully configure user reported message settings, see [User reported settings](submissions-user-reported-messages-custom-mailbox.md).
Admins in Microsoft 365 Government Community Cloud (GCC) or GCC High need to use
> [!NOTE] > Although the screenshots in the remaining steps show the **Report Message** add-in, the steps are identical for the **Report Phishing** add-in.
-2. On the **Integrated apps** page, select the **Report Message** add-in or the **Report Phishing** add-in by doing one of the following steps:
+2. On the **Deployed apps** tab of the **Integrated apps** page, select the **Report Message** add-in or the **Report Phishing** add-in by doing one of the following steps:
- - In the **Name** column, click the icon or text for the add-in. This selection takes you to the **Overview** tab in the details flyout as described in the next steps.
- - In the **Name** column, click **Γï«** **Edit row**, and then select ![Edit users icon.](../../media/m365-cc-sc-remove-selected-users-icon.png) **Edit users**. This selection takes you to the **Users** tab in the details flyout as described in the next steps.
- - In the **Name** column, click **Γï«** **Edit row**, and then select ![Check usaged data icon.](../../media/m365-cc-sc-remove-selected-users-icon.png) **Check usage data**. This selection takes you to the **Usage** tab in the details flyout as described in the next steps.
+ - In the **Name** column, select the icon or text for the add-in. This selection takes you to the **Overview** tab in the details flyout as described in the next steps.
+ - In the **Name** column, select **Γï«** **Edit row**, and then select :::image type="icon" source="../../media/m365-cc-sc-add-internal-icon.png" border="false"::: **Edit users** to go to the **Users** tab in the details flyout as described in the next step.
+ - In the **Name** column, select **Γï«** **Edit row**, and then select :::image type="icon" source="../../media/m365-cc-sc-show-trends-icon.png" border="false"::: **Check usage data** to go to the **Usage** tab in the details flyout as described in the next step.
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/microsoft-365-admin-center-select-report-message-add-in.png" alt-text="Select the Report Message add-in on the Integrated apps page in the Microsoft 365 admin center." lightbox="../../media/microsoft-365-admin-center-select-report-message-add-in.png":::
Admins in Microsoft 365 Government Community Cloud (GCC) or GCC High need to use
- **Test deployment**: **Yes** or **No**, depending on the option you selected when you [deployed the add-in](#get-the-report-message-or-report-phishing-add-in-for-your-organization) or the selection you change on the **Users** tab. - **Description** - **Host product**: Outlook
- - **Actions** section: Click **Remove app** to remove the app.
- - **Assigned users** section: Click **Edit users** to go to the **Users** tab.
- - **Usage** section: Click **Check usage data** to got to the **Usage** tab.
+ - **Actions** section: Select **Remove app** to remove the app.
+ - **Assigned users** section: Select **Edit users** to go to the **Users** tab.
+ - **Usage** section: Select **Check usage data** to got to the **Usage** tab.
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/microsoft-365-admin-center-report-message-add-in-details-overview-tab.png" alt-text="The Overview tab on the details flyout of the Report Message add-in in the Microsoft 365 admin center." lightbox="../../media/microsoft-365-admin-center-report-message-add-in-details-overview-tab.png"::: - **Users** tab:
- - **Is this a test deployment?**: Leave the toggle at ![Toggle off.](../../media/scc-toggle-off.png) **No**, or set the toggle to ![Toggle on.](../../media/scc-toggle-on.png) **Yes**.
+ - **Is this a test deployment?**: Leave the toggle at :::image type="icon" source="../../media/scc-toggle-off.png" border="false"::: **No**, or set the toggle to :::image type="icon" source="../../media/scc-toggle-on.png" border="false"::: **Yes**.
- **Assign users** section: Select one of the following values: - **Just me** - **Entire organization**
- - **Specific users/groups**: Find and select users and groups in the search box. After each selection, the user or group appears in the **Added users** section that appears below the search box. To remove a selection, click ![Remove selection icon.](../../media/m365-cc-sc-remove.png) on the entry.
+ - **Specific users/groups**: Find and select users and groups in the search box. After each selection, the user or group appears in the **Added users** section that appears below the search box. To remove a selection, select :::image type="icon" source="../../media/m365-cc-sc-remove.png" border="false"::: on the entry.
- - **Email notification** section: **Send email notification to assigned users** and **View email sample** are not selectable.
+ - **Email notification** section: **Send email notification to assigned users** and **View email sample** aren't selectable.
- If you made any updates on this tab, click **Update** to save your changes.
+ If you made any updates on this tab, select **Update** to save your changes.
> [!div class="mx-imgBorder"] > :::image type="content" source="../../media/microsoft-365-admin-center-report-message-add-in-details-users-tab.png" alt-text="The Users tab on the details flyout of the Report Message add-in in the Microsoft 365 admin center." lightbox="../../media/microsoft-365-admin-center-report-message-add-in-details-users-tab.png"::: - **Usage** tab: The chart and details table shows the number of active users over time. - Filter the **Date range** to **7 days**, **30 days** (default), or **90 days**.
- - In the **Report** column, click ![Download icon.](../../media/m365-cc-sc-download-icon.png) **Download** to download the information filtered by **Date range** to the file named **UsageData.csv**.
+ - In the **Report** column, select :::image type="icon" source="../../media/m365-cc-sc-download-icon.png" border="false"::: **Download** to download the information filtered by **Date range** to the file named **UsageData.csv**.
- When you're finished viewing the information on the tabs, click ![Close icon.](../../media/m365-cc-sc-close-icon.png) **Close** to close the details flyout.
+ When you're finished viewing the information on the tabs, select :::image type="icon" source="../../media/m365-cc-sc-close-icon.png" border="false"::: **Close** to close the details flyout.
## User instructions ### Get the Report Message or Report Phishing add-ins for yourself
-1. Do one of the following steps:
+1. Do either of the following steps:
- - Open the Microsoft AppSource at <https://appsource.microsoft.com/marketplace/apps>. On the **AppSource** page, enter **Report message** in the ![Search icon.](../../media/search-icon.png) **Search** box, and then select the **Report Message** or **Report Phishing** in the results.
+ - Open the Microsoft commercial marketplace at <https://appsource.microsoft.com/marketplace/apps>. On the **AppSource** page, enter **Report message** in the :::image type="icon" source="../../media/m365-cc-sc-search-icon.png" border="false"::: **Search** box, and then select the **Report Message** or **Report Phishing** in the results.
- :::image type="content" source="../../media/microsoft-appsource-find-report-message-add-in.png" alt-text="Search results on the Microsoft AppSource page for the Report Message add-in." lightbox="../../media/microsoft-appsource-find-report-message-add-in.png":::
+ :::image type="content" source="../../media/microsoft-appsource-find-report-message-add-in.png" alt-text="Search results on the Microsoft commercial marketplace page for the Report Message add-in." lightbox="../../media/microsoft-appsource-find-report-message-add-in.png":::
- Use one of the following URLs to go directly to the download page for the add-in: - **Report Message**: <https://appsource.microsoft.com/product/office/WA104381180>
Admins in Microsoft 365 Government Community Cloud (GCC) or GCC High need to use
> [!NOTE] > Although the screenshots in the remaining steps show the **Report Message** add-in, the steps are identical for the **Report Phishing** add-in.
-2. On the details page of the add-in, click **Get it now**.
+2. On the details page of the add-in, select **Get it now**.
- :::image type="content" source="../../media/ReportMessageGETITNOW.png" alt-text="The details page of the Report Message add-in where you click Get it now." lightbox="../../media/ReportMessageGETITNOW.png":::
+ :::image type="content" source="../../media/ReportMessageGETITNOW.png" alt-text="The details page of the Report Message add-in where you select Get it now." lightbox="../../media/ReportMessageGETITNOW.png":::
3. If prompted, sign in with your Microsoft account credentials.
-4. When the installation is finished, you'll see the following **Launch** page:
+4. When the installation is finished, you get the following **Launch** page:
:::image type="content" source="../../media/report-message-add-in-launch-page.png" alt-text="The Launch page of the Report Message add-in." lightbox="../../media/report-message-add-in-launch-page.png"::: ### Get the Report Message or the Report Phishing add-ins for yourself in Microsoft 365 GCC or GCC High
-Individual users in Microsoft 365 GCC or GCC High can't get the Report Message or Report Phishing add-ins using the Microsoft AppSource.
+Individual users in Microsoft 365 GCC or GCC High can't get the Report Message or Report Phishing add-ins using the Microsoft commercial marketplace.
## Use the Report Message or the Report Phishing add-ins
-You can use the Report Message or the Report Phishing add-ins to submit false positives (good email that was blocked or sent to the Junk Email folder) and false negatives (unwanted email or phishing that was delivered to the Inbox) in Outlook. For more information, see [Report false positives and false negatives in Outlook](submissions-outlook-report-messages.md).
+In supported versions of Outlook, use the Report Message or the Report Phishing add-ins to submit false positives and false negatives. For more information, see [Report false positives and false negatives in Outlook](submissions-outlook-report-messages.md).