1️⃣ Phishing Reporter compatibility
👉 Shared mailbox
Outlook Phishing Reporter supports shared mailbox since manifest
3.0.0.2(26/09/2024). If the user is on the previous version he needs to update the manifestMobile add-in doesn’t supports shared mailbox due to Microsoft limitation.
👉 Compatible
Microsoft 365 Business licenses (Business Basic, Business Standard, Business Premium) and are signed into Office using their organizational ID
Office 365 Enterprise licenses (E1/E3/E5/F3) and are signed into Office using their organizational ID
Microsoft 365 Enterprise licenses (E3/E5/F3) and are signed into Office using their organizational ID
👉 Not compatible
Office 2016 Pro Plus for Enterprise
Office 2019 & 2021 Pro Plus for Enterprise
On-premise
2️⃣ Outlook desktop version
Version 1701 or later of Microsoft 365 Business licenses (Business Basic, Business Standard, Business Premium), Office 365 Enterprise licenses (E1/E3/E5/F3), or Microsoft 365 Enterprise licenses (E3/E5/F3).
Version 1808 or later of Office Professional Plus 2019 or Office Standard 2019.
Version 16.0.4494.1000 or later of Office Professional Plus 2016 (MSI) or Office Standard 2016 (MSI)
Version 15.0.4937.1000 or later of Office Professional Plus 2013 (MSI) or Office Standard 2013 (MSI)
Version 16.0.9318.1000 or later of Office 2016 for Mac
3️⃣ Outlook Mobile
Available on iOS and Android since manifest
3.0.0.2(26/09/2024).
4️⃣ Updating Phishing Reporter as an admin
Click on the Phishing reporter line, a side-pane will open
Click on “Update Add-in” in the “Action” section
Tick the box: ‘Provide link to manifest file’
Paste this url: https://outlookaddin.tryriot.com/manifest.xml
Follow the steps of the side-pane
The new manifest will take some time to be propagated. users will see the new add-in after 24h or more hours
8. Go to Microsoft Entra admin center and search for “Phishing reporter”, click on it
9. Go to “Autorisations” and “Grant administrator consent for Riot Inc”
5️⃣ Troubleshooting
👉 Is it possible to not grant Write scopes on Microsoft?
Yes, the phishing button doesn’t require Write scopes if you don’t want the button to directly move reported emails to the Trash. To remove these scopes, use https://outlookaddin.tryriot.com/manifest-without-auto-delete.xml instead of https://outlookaddin.tryriot.com/manifest.xml.
👉 Phishing Reporter doesn’t display after installation
It can take up to 48h hours for the add-in to display correctly on user Outlook interface. As explained below, it can also require closing the client and authentificating again.
👉 Authentification sometimes needed for old Outlook version
However, we have two different behaviors.
For people using the heavy version of Outlook, a Web connection to Outlook is sometime required for the button to appear
For people who are on the new version of Outlook, the button appears directly without authentification
👉 Re-authentication sometimes needed
After the installation of the Outlook reporter, the employee needs to logout/login to have the Add-in working.
The best way is to logout, close the browser, and open outlook again.


