Phishing email forwarding overview
Set up phishing and BEC report forwarding from Microsoft 365, Google Workspace, KnowBe4, or Proofpoint PhishAlarm into Radiant Security.
Last updated
Was this helpful?
Set up phishing and BEC report forwarding from Microsoft 365, Google Workspace, KnowBe4, or Proofpoint PhishAlarm into Radiant Security.
Radiant triages user-reported phishing and business email compromise (BEC) reports as part of its alert triage pipeline. To begin triaging these reports, you forward them from your email platform or phishing reporting tool into a Radiant-managed mailbox. This article covers the prerequisites that apply to every forwarding method, the phishing configuration settings in Radiant, and how to choose the right forwarding method for your environment.
The phishing use case requires a few setup steps that other connectors do not. Most importantly, enabling the domains you want Radiant to monitor and choosing whether to triage junk and spam reports. Complete the steps in this article in order.
Before you configure phishing email forwarding, confirm the following:
Important note: The Microsoft Entra ID data feed is required for the phishing use case to work. Without it, Radiant cannot determine which domains belong to your organization and will not triage forwarded reports.
An Email Action Connector is recommended but not required. Without one, Radiant ingests and triages phishing reports but cannot execute response actions such as quarantining messages or disabling forwarding rules.
Phishing configuration in Radiant has two tabs: Monitored Domains, where you enable the domains Radiant should triage reports for, and Phishing Triage Tuning, where you choose whether to triage junk and spam reports alongside phishing reports.
To open the page, sign in to Radiant Security and go to Settings > Organization > Phishing Configuration.
Radiant only triages reports for domains you explicitly enable. This prevents triage of reports unrelated to your organization, such as messages forwarded from personal accounts.
The Triage junk/spam emails toggle controls whether Radiant triages junk and spam reports alongside phishing reports. By default, this setting is enabled.
Note: This setting applies regardless of email platform. You do not need to also configure your email platform to suppress junk or spam forwarding — the Radiant toggle is the canonical control.
Choose one method based on your email platform and reporting tool. You only need to configure one of the following.
Note: Microsoft 365 customers using KnowBe4 have two options — the native Microsoft 365 path and the KnowBe4 path. Use the KnowBe4 path if the Phish Alert Button is your standard reporting tool. Use the native Microsoft 365 path if users report through the built-in Microsoft Report Phishing button.
After you complete a forwarding setup, confirm Radiant is ingesting and triaging reports correctly:
Send a test message to a mailbox in your organization and report it as phishing using your standard reporting tool.
Sign in to Radiant Security and check the Alerts and Cases tabs for the triaged report.
If the report does not appear, see the troubleshooting guidance in your platform-specific forwarding article.
Last updated
Was this helpful?
Was this helpful?