Forward phishing emails from Outlook on the web
Use Outlook on the web inbox rules to forward user-reported phishing emails to Radiant Security from a single mailbox without changing tenant-wide forwarding policy.
In this article, you create an inbox rule in Outlook on the web that forwards messages from a single mailbox to Radiant Security based on conditions you define. Inbox rules let you forward a subset of messages (e.g, reports from a specific group of users or messages matching a subject pattern) without changing tenant-wide forwarding policy.
Prerequisites
Before you create the inbox rule, confirm the following:
Create the conditional forwarding rule
Configure the rule name, condition, and action
Set the following:
Name:
Forward to Radiant SecurityCondition: From the Add a condition dropdown, select the condition that matches the messages you want to forward. The example below uses From to match messages from specific senders.
Action: From the Add an action dropdown, select Redirect, then enter
alerts@report.radiantsecurity.ai.
Stop processing more rules
Select the Stop processing more rules checkbox. This prevents other rules from acting on a message after it has been redirected to Radiant.
Important note: Outlook processes inbox rules top to bottom and applies the first matching rule. If you have other rules that should run before the forwarding rule, move them higher in the rule list and leave Stop processing more rules disabled on those rules.
Verify the integration
After you save the rule, confirm reports are reaching Radiant:
Send a message to the mailbox where you created the rule. The message must match the condition you set (e.g., if you used From, send the test message from one of the listed sender addresses).
Sign in to Radiant Security and check the Alerts and Cases tabs for the triaged report.
If the report does not appear, confirm the following:
The rule's condition matches the test message you sent.
The redirect action is set to exactly
alerts@report.radiantsecurity.ai.The forwarding rule is positioned above any other rule that might process the message first.
The mailbox owner's domain is enabled in Radiant's Monitored Domains tab.
Last updated
Was this helpful?

