Skip to content
← Back to the guide

Investigating a phishing message that got past defences

8slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 8

Investigating a phishing message that got past defences

Runbook for a phish that landed: find every copy, purge it from mailboxes, find who clicked, submit it so filters learn, and work out why it got through.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-phishing-message-investigation-runbook

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 8
01

Step 1: get the sample, not a forward

A forwarded phish loses its headers. Get the original via the user's Report button (which lands it in Submissions for you), or from the user's mailbox as an .eml. From the headers you need the sender address, the envelo…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-phishing-message-investigation-runbook

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 8
02

Step 2: find every copy

Open Threat Explorer (Email & collaboration → Explorer), view All email, and search on the sender address, then on the subject, then on the sending IP, over the last 30 days. Campaigns rotate sender addresses but reuse…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-phishing-message-investigation-runbook

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 8
03

Step 3: pull it from mailboxes

From Explorer, select the messages and Take action → Soft delete (recoverable by the user from Deleted Items, which is what you want if you got the verdict wrong) or Hard delete for confirmed malware. This works on mess…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-phishing-message-investigation-runbook

Slide 4Download PNG
M
solvingmicrosoft365.com
5 / 8
04

Step 4: who clicked, and what happened next

Explorer's URL view, the Top clicks tab, and UrlClickEvents in advanced hunting show every Safe Links click with its verdict — Allowed, Blocked, Clicked through. Anyone with a click on a credential-harvesting page is a…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-phishing-message-investigation-runbook

Slide 5Download PNG
M
solvingmicrosoft365.com
6 / 8
05

Step 5: submit it, and block what needs blocking

Submissions → Submit to Microsoft → the message, marked Should have been blocked. This is not bureaucracy; it feeds the filter and, for a real miss, tends to result in tenant-wide detection within hours. Submit the URL…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-phishing-message-investigation-runbook

Slide 6Download PNG
M
solvingmicrosoft365.com
7 / 8
06

Step 6: why did it get through

This is the step that reduces the next one. Work down the list:

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-phishing-message-investigation-runbook

Slide 7Download PNG
M
solvingmicrosoft365.com
8 / 8
07

Close it out

Tell the reporting user thank you, specifically. Users who get thanked report the next one; users who get a lecture stop reporting. Send a short notice to the other recipients if the message was still in inboxes when yo…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-phishing-message-investigation-runbook

Slide 8Download PNG

Auto-generated from Investigating a phishing message that got past defences. This page is not indexed and isn't part of the guide itself.