Question
How can we prevent Outlook (or other email clients) from automatically preventing downloading of pictures? Now phishing campaigns and notifications aren't looking real.
Answer
You will need to add the phishing domains to the Exchange Safe Senders list. Microsoft has provided documentation around how to use Group Policy Settings to deploy a list of domains to your end user's Safe Senders List. You can find more information about how to set this up by visiting one of the links below:
- https://support.microsoft.com/en-us/help/2252421/how-to-deploy-junk-email-settings-such-as-the-safe-senders-list-by-usi
- https://support.office.com/en-us/article/block-or-unblock-automatic-picture-downloads-in-email-messages-15e08854-6808-49b1-9a0a-50b81f2d617a
Integration
Exchange and Microsoft 365
Before setting up the Safe Sender’s List, you will first want to verify that the AZ module and Exchange cmdlets are installed within your PowerShell environment. Instructions can be found on Microsoft Knowledge Base articles on performing these tasks.
Using this methodology, the Safe Senders list distributes to all Outlook environments, including Outlook desktop client, Outlook Web Application, and Outlook Mobile App.
After the modules and cmdlets have been installed, you will log into Azure AD using PowerShell.
- Select Start > Right Click on PowerShell > Run as Administrator
- Type connect-azaccount. A prompt will popup requesting credentials to log into Azure AD.
- After the credentials have been entered, PowerShell will display the account user and tenant ID.
- The following syntax is used to add trusted senders and domains:
Adding Safe Domain
Get-Mailbox | Set-MailboxJunkEmailConfiguration -TrustedSendersAndDomains @{Add=”domain1.com”}
Adding Safe Sender
Get-Mailbox | Set-MailboxJunkEmailConfiguration -TrustedSendersAndDomains @{Add=”user@domain2.com}
Adding Safe Sender and Domain
Get-Mailbox | Set-MailboxJunkEmailConfiguration -TrustedSendersAndDomains @{Add=”domain3.com”,”user@domain4.com”}
Adding Multiple Safe Domains
Get-Mailbox | Set-MailboxJunkEmailConfiguration -TrustedSendersAndDomains @{Add=”domain5.com”,”domain6.com”,”…}
The most up-to-date listing of domains can be found in the Safelisting Guide .
Carlos Rios
Comments