How to add the Cyberaware phishing report button to Outlook

Add a phishing report button to Outlook in 2026: deploy Microsoft's built-in Report Phishing add-in or Cyber Aware's button, step by step for Microsoft 365 admins.

Adding a phishing report button to Outlook takes most Microsoft 365 organisations one admin step and about ten minutes: deploy Microsoft's built-in Report Phishing add-in (or Cyber Aware's one-click reporting button) centrally from the Microsoft 365 admin centre, and every Outlook user gets a native button without touching their device. This guide covers both routes, what each one does, and how to wire reports into your awareness programme.

Why a report button matters more than another training module

Reporting is the behaviour that actually protects the business. A click on a real phishing email costs you only if nobody flags it; the person who reports it starts the response clock. That is why programmes measure report rate alongside click rate - report rate should rise even before click rates fall, because reporting is the habit you can reinforce on every simulation.

In 2026 there are two buttons worth knowing about, and they do different jobs:

Many organisations run both: Microsoft's button for threat intelligence, Cyber Aware's for training and human-risk reporting. They are not mutually exclusive.

Option 1: Deploy Microsoft's built-in Report Phishing button (admin method)

This is Microsoft's first-party add-in. It ships free with Microsoft 365 and can be installed for the whole organisation from the admin centre - no per-device install, no user action.

Step-by-step

  1. Sign in to the Microsoft 365 admin centre at admin.microsoft.com with admin rights.
  2. Go to Settings > Integrated apps, then select Get apps (or search the Microsoft AppSource catalogue inside the admin centre).
  3. Search for Report Phishing (published by Microsoft Corporation) and select it.
  4. Choose Deploy and select All users, then accept the permissions request.
  5. Optionally configure the reporting mailbox: in the Microsoft Defender portal (security.microsoft.com), under Settings > Email & collaboration > User reported settings, set a custom mailbox so user reports are also copied to your security team.
  6. Allow up to 24 hours for propagation - the button appears in the Outlook ribbon across desktop, web and mobile.

For organisations that prefer Defender policies, the same add-in can be rolled out under Microsoft Defender > Email & collaboration > Policies & rules > Threat policies > User reported settings, which is also where you control what users see after they report.

What the built-in button does

It submits the message to Microsoft for analysis and, if configured, forwards a copy to your security mailbox. It is threat reporting, not training reporting - Microsoft does not feed it into any awareness platform.

Option 2: Cyber Aware's phishing report button

Cyber Aware's button plugs into the awareness programme rather than Microsoft's filter. When a user reports an email - simulated or real - the report is logged against their learner record, feeds their Human Risk Score, and lets you celebrate good reporting behaviour rather than just counting clicks.

Step-by-step

  1. Get the deployment package from your Cyber Aware admin dashboard - the add-in works with Microsoft 365 (Outlook desktop, web and mobile).
  2. Deploy centrally: in the Microsoft 365 admin centre, go to Settings > Integrated apps > Upload custom apps and upload the Cyber Aware add-in package, assigning it to all users (or a pilot group first).
  3. Connect the reporting endpoint with your Cyber Aware API key in the add-in settings, so every report lands in your campaign reporting.
  4. Verify in Outlook: the button appears in the ribbon after propagation (allow up to 24 hours), and a test report should appear in your Cyber Aware dashboard.
  5. Wire it into the programme: align the button with your phishing simulations so reporting a simulated email is scored as the correct action - never as a failed click.

If you also use Cyber Aware's training, reported emails can trigger a short reinforcement lesson automatically - the same pattern as click-remediation, but rewarding the behaviour you want.

Rolling out without friction

Troubleshooting

SymptomLikely causeFix
Button not visible for some usersDeployment scoped to a group, or propagation still runningCheck the app's assignment in Integrated apps; allow 24 hours
Button visible but reports not arriving in dashboardEndpoint or API key misconfiguredRe-check the add-in settings against your Cyber Aware dashboard instructions
Reports landing but not scoredSimulated emails not linked to campaignsConfirm campaign scheduling so simulations are recognised when reported
Users report legitimate emailNormal behaviour - reporting is freeNever punish it; a wrong report costs minutes, a missed phish costs far more

FAQ

Is the Outlook Report Phishing button free? Microsoft's built-in add-in is free and included with Microsoft 365. Cyber Aware's report button is part of the Cyber Aware platform - check current pricing with the team.

Can we deploy the phishing report button without users doing anything? Yes. Both add-ins support central deployment from the Microsoft 365 admin centre, which installs the button for all users automatically.

Does the built-in button work in Outlook on the web and mobile? Yes. Microsoft's Report Phishing add-in surfaces across desktop, Outlook on the web and mobile once deployed centrally.

Should we use Microsoft's button, Cyber Aware's, or both? Both is common: Microsoft's for threat intelligence and filter feedback, Cyber Aware's for reporting that feeds training scores and campaign measurement. They work side by side in the ribbon.

Will a user get in trouble for reporting a simulated phishing email? No - reporting a simulation is the correct action and should be scored as a win in your Human Risk Reporting, never as a mistake.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.