> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Phish Alert Button for Outlook

> Deploy Cimento's report button to Outlook so employees can send suspicious email to your security team in one click.

The Phish Alert Button adds a **Report as Phishing** button to Outlook. When an employee reports a real email, Cimento forwards it to your reporting inbox. When they report a Cimento simulation, they're told it was a test and the report counts toward their results.

## Before you start

* **A reporting inbox.** Choose a mailbox your security team monitors, such as a shared mailbox, and send its address to your Cimento contact, who sets it for your organization. Reports fail until it's set.
* **An admin to deploy the add-in.** A Global Administrator, or an Exchange Administrator who also has the Application Administrator role, in the Microsoft 365 admin center.
* **Your email domains registered with Cimento.** The button finds your organization from each employee's email domain.
* **Supported versions of Outlook.** The button works in Outlook on the web, the new Outlook for Windows and Mac, and classic Outlook for Windows version 2409 or later. It isn't available in Outlook mobile.

## Steps

<Steps>
  <Step title="Confirm your reporting inbox">
    Check with your Cimento contact that your reporting inbox is set before you deploy the button.
  </Step>

  <Step title="Open Integrated apps">
    Sign in to the [Microsoft 365 admin center](https://admin.microsoft.com) and go to **Settings › Integrated apps**. Click **Add-ins** near the top of the page, then **Deploy Add-in**, and **Next**.
  </Step>

  <Step title="Find the add-in">
    Choose the option to add an add-in from Microsoft Marketplace, which the wizard may call the **Office Store**. Search for **Cimento AI**, select the Phish Alert Button, and accept the terms. Your Cimento contact can also send you a direct link to the listing.
  </Step>

  <Step title="Choose who gets it">
    Select **Everyone**, or **Specific users/groups** to start with a pilot group. Microsoft deploys only to top-level groups: members of nested groups don't get the button.
  </Step>

  <Step title="Review permissions and deploy">
    Review the permissions the add-in requests (listed below), accept them for your organization, and click **Deploy**. If an employee later sees **Admin Approval Required** in the button, they can copy the approval link to you. Open it as an admin and accept.
  </Step>

  <Step title="Wait for it to appear">
    The button can take 24 to 72 hours to appear in Outlook, and employees may need to restart Outlook to see it.
  </Step>

  <Step title="Test it">
    As a pilot user, open an email and click **Report as Phishing**, then **Report**. Check that the report arrives in your reporting inbox. Try it on a Cimento simulation too: the button should say it was a simulation.
  </Step>
</Steps>

## What happens when an employee reports

* **A Cimento simulation.** The button shows **This was a Phishing Simulation**, nothing is forwarded, and the report counts toward the employee's results.
* **Any other email.** Cimento sends a report from the employee's mailbox to your reporting inbox. It has the original subject, a short summary, the original message attached as `message.eml`, and a screenshot. A copy stays in the employee's **Sent Items**. When the employee clicks **OK**, the reported message moves to **Deleted Items**.

## Permissions

The button has its own Microsoft Entra application, separate from [Microsoft 365 Direct Inject](/integrations/microsoft-365). Its Microsoft Graph permissions are all delegated: it acts only in the mailbox of the employee who clicks the button, and only when they click it.

| Permission | What Cimento uses it for |
| - | - |
| `Mail.ReadWrite` | Reads the reported message so it can be forwarded, and moves it to **Deleted Items** when the employee confirms. |
| `Mail.Send` | Sends the report from the employee's mailbox to your reporting inbox. |
| `User.Read`, `openid`, `profile`, `email` | Signs the employee in, so Cimento knows whose mailbox and organization the report comes from. |

In Outlook, the add-in also requests the **read/write mailbox** permission. Outlook requires that level for the call the add-in uses to identify the selected message.

## Remove the button

In the Microsoft 365 admin center, open **Settings › Integrated apps**, select the add-in and remove it. Only the admin who deployed it, or a Global Administrator, can remove it.
