Skip to main content

Direct Inbox Delivery - Microsoft

API-based Whitelisting

The Microsoft Email Delivery integration replaces manual whitelisting procedures and guarantees the secure delivery of Arsen simulation emails to the inbox in just a few clicks.


1 - Objectives

  • Simplify the whitelisting process on Microsoft 365.

  • Ensure reliable inbox delivery of Arsen phishing simulation emails.

  • Automate the configuration without manual setup in Exchange or Microsoft Defender.


2 - Prerequisites

  • Ability to authorize the installation of a third-party application in Microsoft 365.

  • Ideally, use a dedicated account (Global Administrator or Privileged Role Administrator).


3 – Delegate the integration setup

When an Arsen account is created:

  • Arsen automatically detects your email provider

If your organization uses Microsoft, you can:

  • Perform the installation yourself if you are a Microsoft environment administrator

  • Share the instructions using Share Onboarding Link if another person must perform the integration

3.1 – Send the instructions

To send the setup instructions to an administrator:

  • Click Share Onboarding Link

Arsen onboarding screen showing the organization provider selection with Microsoft 365 selected and the “Share Onboarding Link” button highlighted for non-admin users
  • Enter the administrator’s email address. Click Generate Link
    ​

Arsen partner portal showing the “Share Onboarding Portal” panel with the “Generate Link” button.

  • Using this link, the recipient can access a limited console available for 15 days.

Arsen onboarding page in demo mode showing the main steps: employee synchronization and email delivery configuration.

3.2 - Set up of the integration

  • Click Set Up Email Delivery

  • Click the Microsoft tile.

  • Click Direct Inbox Delivery

Arsen screen allowing selection of the email delivery method for the demo, with the recommended option “API – Direct Inbox Delivery” highlighted.
  • Click Connect to Microsoft 365

Arsen page showing the step “Allow Arsen to send emails via API,” explaining secure use of the Microsoft API for phishing simulations.
  • The administrator is redirected to Microsoft 365 to approve the integration.

Microsoft consent window requesting authorization for the Arsen Phishing Simulation application to access user profiles and mailbox emails.

  • The integration setup is now complete.

Arsen onboarding page indicating that the “Set Up Email Delivery” step is completed, while employee synchronization remains pending.


​


4. Set up the integration directly from Arsen

You are a Microsoft administrator for the organization.

When the Arsen account is created, Arsen automatically detects that Microsoft is the email provider for the configured domain.

  • Click Enable Phishing simulation with Microsoft 365

Arsen screen for selecting the organization provider with Microsoft 365 chosen to connect Arsen and start phishing simulations.
  • A side panel opens. Click one the Connect to Microsoft 365 button.

Arsen step “Enable phishing simulation with Microsoft 365” highlighted, allowing Arsen to deliver emails via Microsoft APIs.

  • Click Accept to confirm the integration

Microsoft consent window requesting permission for the Arsen Phishing Simulation application to access user profiles and mailbox emails.

  • The integration setup is complete.

Arsen onboarding page showing the “Enable phishing simulation with Microsoft 365” step validated with a green checkmark.
Did this answer your question?