More Microsoft Woes and a Little Add Blocker Problem

Hi everyone, 

We are running into a new problem with our Phishing emails and Office 365. All of the users are receiving the emails, however, in the case of the word documents that come as attachments, when our users open them, the documents open in safe mode because they come in an email. This prevents the script from running and no reporting occurs. 

Would love to know how to get around this. From what I gather, this link: https://support.sophos.com/support/s/article/KB-000037983?language=en_US only describes how to stop Exchange Online from blocking the emails outright. 

In the case of campaigns with links as the bait, those emails come through fine as well, however, our Add-Blocker is blocking the links when the users click them. We use Ublock Origin. 

Has anyone had any experience tuning Ublock Origin and if so, is that something that can be done via Group Policy? 

Phish Threat has really helped our company foster and develop a safer email community but there are an increasing number of hoops we are having to jump through between MS and Sophos which is making it more and more difficult to use.

Don't lose track of the Golder Rule of cyber... If it's too hard to use, nobody is going to use it.



Edited TAGs
[edited by: emmosophos at 7:57 PM (GMT -8) on 1 Mar 2024]
Parents
  • Well we figured out how to get around the uBlock Origin add blocker blocking the links in the Link Phish Campaigns (see below) but we are not sure what to do about the docx files opening in safe mode and being blocked. 

    I started a ticket with Sophos and their official response was "It's not on Sophos' end." While I have to agree with them, I don't quite accept that as a full on answer. The attachments worked fine until about a month ago. We made no changes to our O365 settings, but somehow, the attachments all started defaulting to "open in safe mode."

    If this was a MS update, I have to think that others will start to see this behavior as well. As it stands, the document phish campaigns are now useless to us. Are any of you experiencing this behavior? 

    The fix for the uBlock Origin add blocker was found on Reddit, posted by DefinitelyYou: https://www.reddit.com/r/uBlockOrigin/comments/o7q2ou/control_trusted_sites_with_gpo/

Reply
  • Well we figured out how to get around the uBlock Origin add blocker blocking the links in the Link Phish Campaigns (see below) but we are not sure what to do about the docx files opening in safe mode and being blocked. 

    I started a ticket with Sophos and their official response was "It's not on Sophos' end." While I have to agree with them, I don't quite accept that as a full on answer. The attachments worked fine until about a month ago. We made no changes to our O365 settings, but somehow, the attachments all started defaulting to "open in safe mode."

    If this was a MS update, I have to think that others will start to see this behavior as well. As it stands, the document phish campaigns are now useless to us. Are any of you experiencing this behavior? 

    The fix for the uBlock Origin add blocker was found on Reddit, posted by DefinitelyYou: https://www.reddit.com/r/uBlockOrigin/comments/o7q2ou/control_trusted_sites_with_gpo/

Children