Skip to main content

Configure Advanced Delivery Policies

Microsoft Advanced Delivery Policies

Updated over a month ago

Before testing your employees, your mail servers must be configured so that Arsen phishing simulations are delivered directly to the inbox instead of being filtered as spam.

This procedure complements IP whitelisting and ensures that Microsoft 365 correctly authorizes Arsen’s attack domains.


1 – Objectives

  • Ensure delivery of Arsen simulations to the inbox.

  • Create Advanced Delivery Policies to authorize up to 30 attack domains.

  • Configure Microsoft Defender and Exchange Online to recognize Arsen simulations.

  • Complete IP whitelisting with domain- and URL-based authorization.


2 – Prerequisites

You must have one of the following Microsoft 365 versions:

  • Exchange Online Protection

  • Microsoft Defender for Office 365 Plan 1 or Plan 2

  • Microsoft Defender XDR

Required permissions:

  • Member of the Security Administrator role in the Microsoft Security Center.

  • Member of the Organization Management role in Exchange Online.

Additional requirements:

  • Pre-select up to 30 Arsen attack domains
    (Microsoft allows a maximum of 30 third-party domains in an Advanced Delivery Policy)
    → Available in Settings → Phishing Domains.

  • Have previously whitelisted Arsen IPs:

    • 161.38.204.14

    • 185.211.123.249


3 – Create Advanced Delivery Policies

3.1 – Access the configuration settings

  • Sign in to your Microsoft account.

  • Open Microsoft 365 Defender.

  • Under Email & Collaboration, navigate to:
    Policies & RulesThreat PoliciesAdvanced Delivery

  • Select the Phishing Simulation tab.

  • Click Edit or Add to configure a new Advanced Delivery Policy.

Microsoft 365 settings screen showing Phishing Simulation configuration with fields for sending domain, sending IP address, and authorized simulation URLs

3.2 – Add the required configuration elements

Add your selected Arsen domains (up to 30)

These include:

  • Arsen-provided attack domains

  • Any custom domains validated in Arsen

Add the Arsen IP addresses:

  • 161.38.204.14

  • 185.211.123.249

Add URLs associated with each domain:

For every domain, add the wildcard version:

*.domain1/* *.domain2/* *.domain3/*

Example

*.office355.net/* *.sharepointonllne.com/* *.ms-certified.com/*

These entries ensure that all subdomains are authorized.

Click Save to finalize the configuration.

For more details, refer to Microsoft’s official documentation on Advanced Delivery Policies.

Did this answer your question?