My Microsoft Attack Simulator emails get quarantined when user's report them, why is that?

Alyse Hart 25 Reputation points

I am working on creating a phishing simulation for my organization; normally when we have a phishing campaign simulation, we send a copy of our reported emails to our shared security team mailbox. This gives us quick reference for user reports and forwards.

In a recent simulation test, I am able to receive the message in my inbox, but when I report, it goes straight to quarantine or gets ZAPped shortly after it's delivered to the shared inbox with the detection technology 'File Reputation'. This is the case, as the payload type is a Link in Attachment. Is there a way that I can prevent this this from happening?

For context: here are some of the key components I used in the simulation: Phishing URL - https[:]//www[.]techidal[.]com Document Type - Docx

Not Monitored
Not Monitored
Tag not monitored by Microsoft.
36,403 questions
0 comments No comments
{count} votes