How to fix false positives with phish test results?

Cedric R. Porties 0 Reputation points
2025-01-29T22:05:32.95+00:00

Why am I getting false positives with phish simulation training results?

Exchange Online
Exchange Online
A Microsoft email and calendaring hosted service.
6,178 questions
Microsoft 365 and Office | Install, redeem, activate | For business | Windows
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-01-30T07:14:29.47+00:00

    Hi @Cedric R. Porties,

    Welcome to the Microsoft Q&A platform!

    According to your description, you are experiencing false positive issues in phishing simulation training. Here are some common reasons why they may occur:

    1. Many organizations use security tools to automatically scan and click links in emails to check for malicious content. These automated clicks may be mistaken for user interactions, resulting in false positives.
    2. Some third-party email security services scan and detonate links in emails as part of their protection measures. If these actions are recorded as user clicks, this can also lead to false positives.
    3. When using third-party reporting tools, simulated phishing emails may be scanned, trigger links and cause false positives.
    4. Sometimes, checking the IP addresses associated with clicks can reveal that they come from security services rather than actual users.

    To mitigate these issues, you can:

    1. Implement allowlist measures for your phishing simulation emails to prevent security tools from interacting with them.
    2. Utilize dedicated phishing simulation reporting tools designed to minimize false positives.
    3. Conduct detailed investigations to determine the source of false positives and adjust security settings accordingly.

    Please feel free to contact me for any updates. And if this helps, don't forget to mark it as an answer.

    Best,

    Jake Zhang


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.