Can AttackSimulation be provided with an external url?

Adi Malyanker 70 Reputation points
2023-12-28T14:24:01.44+00:00

Hi,

Can Attack Simulation be provided with an external URL in the free text field (the field in the Attack Simulation creation process, where the user can add their custom text )?

What will happen in case any user clicks on this URL? Will they be redirected to the external website?

Thanks,

Adi

Microsoft 365 and Office Install, redeem, activate For business Windows
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 157.4K Reputation points MVP Volunteer Moderator
    2023-12-28T14:56:52.36+00:00

    You can :

    https://techcommunity.microsoft.com/t5/security-compliance-and-identity/the-attack-simulation-training-landing-page-is-now-customizable/ba-p/2777460

    but take note:

    Note

    Check the availability of the simulated phishing URL in your supported web browsers before you use the URL in a phishing campaign. While we work with many URL reputation vendors to always allow these simulation URLs, we don't always have full coverage (for example, Google Safe Browsing). Most vendors provide guidance that allows you to always allow specific URLs (for example, https://support.google.com/chrome/a/answer/7532419).

    https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training-get-started?view=o365-worldwide#simulations

    User's image

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Q&A Assist
    2023-12-28T14:24:01.4433333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Yes, Attack Simulation training allows you to provide a custom URL in the free text field during the creation of a simulation. If a user clicks on this URL, they will be redirected to the external website. However, it is important to note that you should check the availability of the URL in your supported web browsers before using it in a phishing campaign, as some URL reputation vendors may identify it as unsafe. Additionally, some network proxy solutions and filter drivers may block or drop phishing simulation URLs and admin URLs, so it is recommended to configure the required URLs to bypass scanning by your security devices or filters as needed.


    References:

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.