Microsoft Report Button - Activating the integration with Nimblr
A brief guide on how to connect your Microsoft Report Button to Nimblr
Connecting your Microsoft Report Button to Nimblr will allow your administrators to track and display in your portal which users are in fact reporting the Nimblr Phishing Simulations or not.
Create a new shared mailbox
-
Go to: https://admin.cloud.microsoft/?#/SharedMailbox and create a new shared mailbox
-
Go to: https://security.microsoft.com/ and go to the “Email & Collaboration” > “User reported settings”
-
Set “Send reported messages to:” > “Microsoft and my reporting” mailbox
-
Select the shared mailbox you just created.
Create and configure a New App Registration
-
Sign in to Microsoft Entra
-
Go to the Applications tab: https://entra.microsoft.com/#view/Microsoft_AAD_RegisteredA pps/ApplicationsListBlade/
-
Navigate to: All applications > New registration
-
Create a new app registration
-
Go to API permissions and click: Add a permission
-
Select Microsoft Graph and then choose: Application permissions
-
Select Mail.Read and Save
-
Grant Admin consent for this permission
-
Go to Certificates and secrets and create a new secret
-
Copy the Value (Not the secret ID) and paste it in a text document for later
-
Go to Overview and copy: Application (client) ID and Directory (tenant) ID in the same document as the Client secret
Configure in the Nimblr Portal
-
Go to Settings tab > Report Button >
-
Fill in the following credentials: Application (client) ID, Directory (tenant) ID and Client secret
-
Select the mailbox you created in step 1.
-
Now it's Done!
Limiting the permissions (Optional)
-
Open up PowerShell
Run the following command to sign in:
-
Connect-ExchangeOnline -UserPrincipalName
Create a new distribution group:
-
New-DistributionGroup-Name "API-Access-Group-V2 Security" -Members -Type Security
Add the policy:
-
New-ApplicationAccessPolicy-AppId "" PolicyScopeGroupId " @" AccessRight RestrictAccess -Description "Restrict app to shared mailbox only"
Allow up to 48 hours for the policy to take effect.