Phishing email forwarding overview
Set up phishing and BEC report forwarding from Microsoft 365, Google Workspace, KnowBe4, or Proofpoint PhishAlarm into Radiant Security.
Radiant triages user-reported phishing and business email compromise (BEC) reports as part of its alert triage pipeline. To begin triaging these reports, you forward them from your email platform or phishing reporting tool into a Radiant-managed mailbox. This article covers the prerequisites that apply to every forwarding method, the phishing configuration settings in Radiant, and how to choose the right forwarding method for your environment.
The phishing use case requires a few setup steps that other connectors do not. Most importantly, enabling the domains you want Radiant to monitor and choosing whether to triage junk and spam reports. Complete the steps in this article in order.
Prerequisites
Before you configure phishing email forwarding, confirm the following:
Important note: The Microsoft Entra ID data feed is required for the phishing use case to work. Without it, Radiant cannot determine which domains belong to your organization and will not triage forwarded reports.
An Email Action Connector is recommended but not required. Without one, Radiant ingests and triages phishing reports but cannot execute response actions such as quarantining messages or disabling forwarding rules.
Configure phishing settings in Radiant
Phishing configuration in Radiant has two tabs: Monitored Domains, where you enable the domains Radiant should triage reports for, and Phishing Triage Tuning, where you choose whether to triage junk and spam reports alongside phishing reports.
To open the page, sign in to Radiant Security and go to Settings > Organization > Phishing Configuration.
Enable monitored domains
Radiant only triages reports for domains you explicitly enable. This prevents triage of reports unrelated to your organization, such as messages forwarded from personal accounts.
Choose how to handle junk and spam reports
The Triage junk/spam emails toggle controls whether Radiant triages junk and spam reports alongside phishing reports. By default, this setting is enabled.
Choose a forwarding method
Choose one method based on your email platform and reporting tool. You only need to configure one of the following.
Verify ingestion
After you complete a forwarding setup, confirm Radiant is ingesting and triaging reports correctly:
Send a test message to a mailbox in your organization and report it as phishing using your standard reporting tool.
Sign in to Radiant Security and check the Alerts and Cases tabs for the triaged report.
If the report does not appear, see the troubleshooting guidance in your platform-specific forwarding article.
Last updated
Was this helpful?

