Adding a phishing report button to Outlook takes most Microsoft 365 organisations one admin step and about ten minutes: deploy Microsoft's built-in Report Phishing add-in (or Cyber Aware's one-click reporting button) centrally from the Microsoft 365 admin centre, and every Outlook user gets a native button without touching their device. This guide covers both routes, what each one does, and how to wire reports into your awareness programme.
Why a report button matters more than another training module
Reporting is the behaviour that actually protects the business. A click on a real phishing email costs you only if nobody flags it; the person who reports it starts the response clock. That is why programmes measure report rate alongside click rate - report rate should rise even before click rates fall, because reporting is the habit you can reinforce on every simulation.
In 2026 there are two buttons worth knowing about, and they do different jobs:
- Microsoft's built-in Report Phishing add-in - free, native in Outlook, sends the suspicious email to Microsoft and (optionally) to your security mailbox. It improves Microsoft's filtering for everyone.
- Cyber Aware's phishing report button - sends the reported email into your awareness programme, so reports are logged per person and can be celebrated and scored alongside simulations.
Many organisations run both: Microsoft's button for threat intelligence, Cyber Aware's for training and human-risk reporting. They are not mutually exclusive.
Option 1: Deploy Microsoft's built-in Report Phishing button (admin method)
This is Microsoft's first-party add-in. It ships free with Microsoft 365 and can be installed for the whole organisation from the admin centre - no per-device install, no user action.
Step-by-step
- Sign in to the Microsoft 365 admin centre at admin.microsoft.com with admin rights.
- Go to Settings > Integrated apps, then select Get apps (or search the Microsoft AppSource catalogue inside the admin centre).
- Search for Report Phishing (published by Microsoft Corporation) and select it.
- Choose Deploy and select All users, then accept the permissions request.
- Optionally configure the reporting mailbox: in the Microsoft Defender portal (security.microsoft.com), under Settings > Email & collaboration > User reported settings, set a custom mailbox so user reports are also copied to your security team.
- Allow up to 24 hours for propagation - the button appears in the Outlook ribbon across desktop, web and mobile.
For organisations that prefer Defender policies, the same add-in can be rolled out under Microsoft Defender > Email & collaboration > Policies & rules > Threat policies > User reported settings, which is also where you control what users see after they report.
What the built-in button does
It submits the message to Microsoft for analysis and, if configured, forwards a copy to your security mailbox. It is threat reporting, not training reporting - Microsoft does not feed it into any awareness platform.
Option 2: Cyber Aware's phishing report button
Cyber Aware's button plugs into the awareness programme rather than Microsoft's filter. When a user reports an email - simulated or real - the report is logged against their learner record, feeds their Human Risk Score, and lets you celebrate good reporting behaviour rather than just counting clicks.
Step-by-step
- Get the deployment package from your Cyber Aware admin dashboard - the add-in works with Microsoft 365 (Outlook desktop, web and mobile).
- Deploy centrally: in the Microsoft 365 admin centre, go to Settings > Integrated apps > Upload custom apps and upload the Cyber Aware add-in package, assigning it to all users (or a pilot group first).
- Connect the reporting endpoint with your Cyber Aware API key in the add-in settings, so every report lands in your campaign reporting.
- Verify in Outlook: the button appears in the ribbon after propagation (allow up to 24 hours), and a test report should appear in your Cyber Aware dashboard.
- Wire it into the programme: align the button with your phishing simulations so reporting a simulated email is scored as the correct action - never as a failed click.
If you also use Cyber Aware's training, reported emails can trigger a short reinforcement lesson automatically - the same pattern as click-remediation, but rewarding the behaviour you want.
Rolling out without friction
- Pilot first with 20-50 users for one week, then deploy to all users once nothing breaks.
- Announce it properly. A one-line launch email plus a 3-minute lesson beats a silent ribbon change; adoption follows awareness.
- Add it to induction. New joiners should see the button in their first-week onboarding checklist.
- Decide the feedback loop. Both Microsoft's Defender settings and Cyber Aware's add-in can show users a confirmation message - tell people what happens after they report so the habit sticks.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Button not visible for some users | Deployment scoped to a group, or propagation still running | Check the app's assignment in Integrated apps; allow 24 hours |
| Button visible but reports not arriving in dashboard | Endpoint or API key misconfigured | Re-check the add-in settings against your Cyber Aware dashboard instructions |
| Reports landing but not scored | Simulated emails not linked to campaigns | Confirm campaign scheduling so simulations are recognised when reported |
| Users report legitimate email | Normal behaviour - reporting is free | Never punish it; a wrong report costs minutes, a missed phish costs far more |
FAQ
Is the Outlook Report Phishing button free? Microsoft's built-in add-in is free and included with Microsoft 365. Cyber Aware's report button is part of the Cyber Aware platform - check current pricing with the team.
Can we deploy the phishing report button without users doing anything? Yes. Both add-ins support central deployment from the Microsoft 365 admin centre, which installs the button for all users automatically.
Does the built-in button work in Outlook on the web and mobile? Yes. Microsoft's Report Phishing add-in surfaces across desktop, Outlook on the web and mobile once deployed centrally.
Should we use Microsoft's button, Cyber Aware's, or both? Both is common: Microsoft's for threat intelligence and filter feedback, Cyber Aware's for reporting that feeds training scores and campaign measurement. They work side by side in the ribbon.
Will a user get in trouble for reporting a simulated phishing email? No - reporting a simulation is the correct action and should be scored as a win in your Human Risk Reporting, never as a mistake.