If the alert "Phish delivered due to an ETR override" is triggered due to our phishing simulation, you will not be able to change the alert manually. Please contact your Implementation Manager/ Customer Success Manager or support@sosafe.de to resolve this issue. 

You will be provided with a PowerShell script that creates a custom rule developed by SoSafe that extends the default Microsoft rule to the extent that our servers are excluded,

but the other functionality remains the same.

 

You will need the appropriate Security & Compliance M365 admin rights to run it.

 

Execution: 

1. press Windows key + enter PowerShell in search.

2. run PowerShell as admin.

3. either copy and paste the script or enter the path to the script in PowerShell.

 

Important: After execution, please disable the default "Phish delivered due to an ETR override" rule at https://protection.office.com/alertpolicies. Unfortunately, this cannot be done via PowerShell.


The content of this article and instructions have been created with utmost care. However, due to the diversity of computer systems and the possibility of information becoming outdated (e.g. because of updates), SoSafe GmbH accepts no liability for the topicality, correctness and functionality of the content. Likewise, no liability is assumed for damages or consequential damages resulting from the use of the offered contents.