Skip to main content
The Phish Alert Button adds a Report as Phishing button to Outlook. When an employee reports a real email, Cimento forwards it to your reporting inbox. When they report a Cimento simulation, they’re told it was a test and the report counts toward their results.

Before you start

  • A reporting inbox. Choose a mailbox your security team monitors, such as a shared mailbox, and send its address to your Cimento contact, who sets it for your organization. Reports fail until it’s set.
  • An admin to deploy the add-in. A Global Administrator, or an Exchange Administrator who also has the Application Administrator role, in the Microsoft 365 admin center.
  • Your email domains registered with Cimento. The button finds your organization from each employee’s email domain.
  • Supported versions of Outlook. The button works in Outlook on the web, the new Outlook for Windows and Mac, and classic Outlook for Windows version 2409 or later. It isn’t available in Outlook mobile.

Steps

1

Confirm your reporting inbox

Check with your Cimento contact that your reporting inbox is set before you deploy the button.
2

Open Integrated apps

Sign in to the Microsoft 365 admin center and go to Settings › Integrated apps. Click Add-ins near the top of the page, then Deploy Add-in, and Next.
3

Find the add-in

Choose the option to add an add-in from Microsoft Marketplace, which the wizard may call the Office Store. Search for Cimento AI, select the Phish Alert Button, and accept the terms. Your Cimento contact can also send you a direct link to the listing.
4

Choose who gets it

Select Everyone, or Specific users/groups to start with a pilot group. Microsoft deploys only to top-level groups: members of nested groups don’t get the button.
5

Review permissions and deploy

Review the permissions the add-in requests (listed below), accept them for your organization, and click Deploy. If an employee later sees Admin Approval Required in the button, they can copy the approval link to you. Open it as an admin and accept.
6

Wait for it to appear

The button can take 24 to 72 hours to appear in Outlook, and employees may need to restart Outlook to see it.
7

Test it

As a pilot user, open an email and click Report as Phishing, then Report. Check that the report arrives in your reporting inbox. Try it on a Cimento simulation too: the button should say it was a simulation.

What happens when an employee reports

  • A Cimento simulation. The button shows This was a Phishing Simulation, nothing is forwarded, and the report counts toward the employee’s results.
  • Any other email. Cimento sends a report from the employee’s mailbox to your reporting inbox. It has the original subject, a short summary, the original message attached as message.eml, and a screenshot. A copy stays in the employee’s Sent Items. When the employee clicks OK, the reported message moves to Deleted Items.

Permissions

The button has its own Microsoft Entra application, separate from Microsoft 365 Direct Inject. Its Microsoft Graph permissions are all delegated: it acts only in the mailbox of the employee who clicks the button, and only when they click it. In Outlook, the add-in also requests the read/write mailbox permission. Outlook requires that level for the call the add-in uses to identify the selected message.

Remove the button

In the Microsoft 365 admin center, open Settings › Integrated apps, select the add-in and remove it. Only the admin who deployed it, or a Global Administrator, can remove it.