Sophos Phish Threat: Deploy and operate the Outlook add-in
The Sophos Outlook Add-in provides Outlook users with the Report to Sophos action. It can be used for both genuinely suspicious phishing or spam messages and Phish Threat simulations. Deployment is complete only after forwarding to the designated internal mailbox, the data protection decision, and the user workflow have been verified with a controlled message.
This add-in is part of the reporting and simulation process of Sophos Phish Threat. It is not the encryption add-in and must not be confused with the separate Sophos Email reporting path. Its different scope is described in the runbook for the Report-to-Sophos add-in for Sophos Email.
Define architecture and data protection before the rollout
When reporting, the add-in forwards the message to the mailboxes configured in Sophos Fusion (formerly Sophos Central). By default, a copy also goes to SophosLabs for threat analysis. This allows administrators to examine real reports and Sophos to analyze new threats. However, the transmission may involve message content, attachments, and personal or confidential information.
Before activation, work with data protection, information security, and employee representatives where applicable to determine:
- which internal mailboxes receive reports and who is allowed to access them;
- how long reports are retained and how real incidents are handled;
- whether a copy may be sent to SophosLabs;
- which user information explains the deletion and transmission process;
- which non-confidential message will be used for acceptance testing.
If no copy is to be sent to SophosLabs, disable Send reported emails to SophosLabs for threat analysis in the add-in configuration. The internal reporting mailbox is still required. Document this decision before downloading the manifest and review it again after configuration changes.
Check requirements and supported clients
You need an active Phish Threat environment, access to Sophos Fusion, and an administrator who is authorized to deploy custom Office add-ins in Microsoft 365 or Exchange. Before the change, document the tenant, mail platform, pilot group, target mailboxes, data protection decision, and the Outlook versions actually in use.
The current add-in is intended for the following environments:
- Microsoft Outlook for Windows and Mac;
- Outlook on the web;
- Microsoft Outlook for iOS and Android;
- Microsoft 365 and supported Exchange environments.
The following limitations must be considered before deployment:
- Exchange 2013 is not supported.
- Non-Microsoft mail services such as Gmail and other POP/IMAP accounts are not supported.
- The mobile add-in only works with Microsoft 365 Exchange and not with on-premises Exchange.
- Outlook 2019 for Windows and Mac as well as Outlook 2016 for Windows are not supported; this restriction does not apply to the mobile add-in.
The fact that Outlook can display an account does not prove that the add-in is supported. If the add-in cannot be installed on endpoints or is missing from the list of available add-ins, install the latest Microsoft Office updates first.
Configure reporting mailboxes
The target mailboxes are set up before downloading the manifest:
- In Sophos Fusion open the Global Settings icon.
- Go to Products and Services > Sophos Phish Threat > Outlook Add-in Configuration.
- With Add mailbox, add the intended mailbox or another failover rule.
- Check target addresses, order, and access by the responsible security team.
- Set the option Send reported emails to SophosLabs for threat analysis according to the documented data protection decision.
A technically reachable mailbox is not enough: the responsible team needs a defined triage process for genuine reports. Do not use a personal mailbox or an unattended shared mailbox for the pilot.
Download current XML manifest
After mailbox configuration:
- Go to Sophos Fusion in My Products > Phish Threat > Add-in for Outlook.
- Click on Download under Outlook Add-In.
- Store
SophosOutlookAddinManifest.xmlunchanged in an access-protected location. - Log the download time, the responsible administrator, and the intended assignment scope.
For every new deployment and upgrade, use the current manifest downloaded from your own Sophos Fusion tenant. An older, locally archived XML file is not a reliable starting point.
Deploy pilot in Microsoft 365
Sideloading is intended only for proof of concept and testing by a single user. Before the production rollout, it should be checked whether central Office add-in deployment is supported in the organization. Then the current manifest is first assigned to a small pilot group:
- Sign in to Microsoft 365 Admin Center.
- Open Settings > Integrated Apps.
- Select Upload custom apps.
- Under Upload Apps to deploy in App type, select the option Office Add-in.
- Under Choose how to upload app, choose the option Upload manifest file (.xml) from device and click on Choose File.
- Open
SophosOutlookAddinManifest.xml. Click Next only after the Manifest file validated confirmation appears. - On Add users, choose the option under Is this a test deployment that matches the change. Under Assign users, select Specific users/group for the pilot, or initially Just me; do not select Entire organization straight away. Then select Next.
- On Accept permissions requests click on Accept permissions, check the requested permissions and confirm in the Permission requested dialog with Accept. Record the permissions actually displayed in the tenant-related manifest or consent dialog in the change record, instead of adopting fixed permission names from an older guide.
- Click on Next and then on Review and finish deployment > Finish Deployment.
- After the completion confirmation, select Done. The add-in must appear under Integrated Apps > Deployed apps.
Record the status, manifest, displayed and approved permissions, and assigned pilot users as change evidence. According to Microsoft, a new or changed central deployment can take up to 24 hours to distribute. Do not begin troubleshooting or redeploy until this window has elapsed. Once Desktop/Web and, where applicable, Mobile have been tested successfully, gradually expand the assignment within the same app to additional groups or Entire organization.
In an on-premises Exchange environment without a connection to Microsoft 365, perform the organization-wide installation through the Exchange Admin Center. Do not mix this method with Microsoft 365 deployment. Because the mobile add-in does not support on-premises Exchange, Mobile is not part of the acceptance scope in this environment.
Report a message from the user’s perspective
Outlook Desktop and Outlook on the web
- Select or open the suspicious message.
- Click on Report to Sophos in the Outlook ribbon.
- Confirm the prompt with Yes.
In the new Outlook version for Windows with multiple configured accounts, Report to Sophos under All Apps only appears in the primary account. This is a product-specific limitation and not evidence of an incorrect assignment to the other accounts.
Outlook on iOS and Android
- Open the message.
- Open the ellipsis icon and select Report to Sophos.
- Confirm the prompt with Yes.
After a successful report, a dialog informs the user that the message has been sent to the administrator and deleted from their mailbox. For a Phish Threat simulation message, positive feedback appears immediately instead, confirming the correct response. These two outcomes are explained in user communication so that the deletion of a real report and the simulation feedback are not interpreted as errors.
Validate the pilot and production operation
For acceptance, a pilot user and a clearly recognizable, non-confidential message are used. A simulation is additionally tested separately:
- Check that the user is actually assigned under Deployed apps and that the add-in appears in the intended client.
- Report a normal test message with Report to Sophos > Yes.
- Confirm that the success dialog appears and the message has been deleted from the user’s mailbox.
- In the configured internal mailbox, check that exactly this message with usable message data has been received.
- According to the data protection decision in Sophos Fusion, check and document whether the SophosLabs transmission is enabled or disabled. This test only confirms the configuration state; the actual delivery of a copy to SophosLabs cannot be directly verified through this.
- Report an approved Phish Threat simulation email and confirm the immediate positive feedback in Outlook.
- Check every intended client type and, for mobile specifically, a Microsoft 365 Exchange mailbox.
A visible button alone is not a successful acceptance. Likewise, the receipt in the internal mailbox does not prove that simulation feedback, deletion, and data protection options are functioning correctly.
Rollback and abort criteria
Before the pilot, the approved assignment scope, the target mailboxes, and the state of Send reported emails to SophosLabs for threat analysis are recorded. In case of unexpected message deletion, incorrect routing, a deviation from the data protection approval, or a failed reporting test, the expansion is stopped.
To roll back, remove the pilot assignment or the new app under Settings > Integrated Apps. Reset the target mailboxes and SophosLabs option to their documented initial state only if they were changed as part of the same change. Then allow up to 24 hours for Microsoft distribution and verify on every affected client that Report to Sophos is no longer available. Reports already submitted may still arrive; however, do not submit another test message after the documented abort time.
During an upgrade, do not redeploy the outdated add-in. Until the current deployment is corrected, users should use an approved alternative reporting method; escalate the issue with the evidence listed below.
Migrate old add-in to the current version
For an upgrade, remove the old add-in and then deploy the current manifest downloaded from your own Sophos Fusion tenant. Static version numbers or details about individual token methods are not reliable selection criteria because the version delivered by Sophos can change. Therefore, do not reuse the locally archived manifest – not even for on-premises Exchange environments.
Do not install the new add-in over the old one:
- Open the Microsoft 365 Admin Center Settings > Integrated Apps.
- Select the old add-in Report Message to open the flyout.
- Click Remove App.
- Confirm the selection with X and close the flyout.
- Download the current manifest again from Sophos Fusion and deploy it according to the pilot procedure described above.
A persistent loading indicator when reporting or failed submissions can indicate an outdated deployment. The reliable fix does not consist of searching for a specific script name, banner, or a fixed version number: one removes the old add-in, downloads the manifest again from Sophos Fusion, deploys it to a pilot group, and performs the controlled reporting test.
Narrow down errors and separate responsibilities
Add-in missing only for individual users: A new or changed central deployment may take up to 24 hours to appear. After this period, check the assignment under Deployed apps, the primary account in New Outlook, mailbox type, client version, and Office updates. Then restart Outlook completely. Do not use sideloading as a permanent replacement for a faulty central deployment.
Add-in missing for the entire pilot group: Here, too, first consider the distribution window of up to 24 hours. Then check the manifest, the permissions displayed and approved in the consent dialog, the deployment status, and central deployment capability in Microsoft 365. For local Exchange, ensure that the installation actually occurred via Exchange Admin Center. This is the Microsoft/Exchange deployment limit; changing the Sophos target mailboxes does not fix a missing app assignment.
Reporting never finishes or fails in Exchange Online: Check whether the old Report Message add-in or an archived manifest is still deployed. Remove the old add-in, download the current manifest again from Sophos Fusion, deploy it to a pilot group, and retest after allowing for the Microsoft 365 distribution time. Do not mask an outdated deployment by clicking repeatedly or immediately redeploying it across the organization.
Report is being sent but does not reach the security team: Check target mailboxes and failover rules under Products and Services > Sophos Phish Threat > Outlook Add-in Configuration. Mail routing and access to the target mailbox belong to the mail platform; content, SophosLabs option, and simulation detection belong to the Phish Threat process.
Simulation shows no positive feedback: First confirm that exactly the active Phish Threat simulation message was reported. If a normal report arrives internally, the error is no longer primarily with the manifest or assignment; campaign and message identity are then checked in Phish Threat.
For an escalation, collect the tenant, user and group, mail platform, Outlook platform and exact version, account type, manifest download time, deployment and assignment status, timestamp with time zone, results of a normal report and a simulation, target mailbox, SophosLabs setting, and any dialogs or errors observed. Do not include confidential message text, attachments, credentials, or full tokens in the error log.