Enable Phishing Simulations

ThouShaltNotClick places phishing simulations straight into your staff's inboxes. Your Google Workspace or Microsoft 365 administrator gives us one narrow permission to do that, once. Until it's done, simulations can't reach your staff.

πŸ’‘
Why direct delivery
Simulations never pass through an email provider or your spam filter. That means no allowlisting, and nothing is delayed or sent to junk on the way in. It also changes nothing about how your mail flows: no MX change, no connectors, no routing rules.

Google Workspace

You need a Google Workspace super admin. It takes about two minutes.

  • In ThouShaltNotClick, open Integrations β†’ Enable Phishing Simulations and choose Google Workspace. Keep the Client ID and the OAuth scope handy; each has a Copy button.
  • In the Google Admin console, go to Security β†’ Access and data control β†’ API controls β†’ Manage Domain Wide Delegation. The card links straight there.
  • Click Add new, paste the Client ID and the scope, and click Authorize. The scope is exactly https://www.googleapis.com/auth/gmail.insert.
  • Back on the card, type a staff email address under Check connection. No email is sent. It usually takes effect within a few minutes; if the check says it isn't ready, try again a little later.

What this permission allows: adding a message to a mailbox. It can't read, search, send or delete anything. To remove it, delete the entry on the same Domain Wide Delegation page.

Microsoft 365

You need an Exchange Online administrator who can run PowerShell. Access is limited to the mailboxes you choose, through Exchange Online RBAC for Applications.

⚠️
Don't click β€œGrant admin consent”
Admin consent would give the app access to every mailbox in your organization, and a per-mailbox scope can't narrow it afterwards. The steps below grant access to your staff group only.

Use the App ID shown on Integrations β†’ Enable Phishing Simulations (Microsoft 365 tab) wherever the commands say <APP ID>. Put the staff who should receive simulations in a mail-enabled security group first.

1. Add the app to your tenant, with no permissions

Microsoft Graph PowerShell:

Connect-MgGraph -Scopes "Application.ReadWrite.All" $sp = New-MgServicePrincipal -AppId "<APP ID>" $sp.Id # the app's Object ID in your tenant

2. Give it access to your staff group's mailboxes only

Exchange Online PowerShell. Replace the group's distinguished name and the Object ID from step 1:

Connect-ExchangeOnline New-ServicePrincipal -AppId "<APP ID>" -ObjectId "<OBJECT ID>" -DisplayName "ThouShaltNotClick Practice Emails" New-ManagementScope -Name "TSNC simulations" -RecipientRestrictionFilter "MemberOfGroup -eq '<GROUP DN>'" New-ManagementRoleAssignment -App "<OBJECT ID>" -Role "Application Mail.ReadWrite" -CustomResourceScope "TSNC simulations"

3. Check it

Changes take 30 minutes to 2 hours to apply. Then:

Test-ServicePrincipalAuthorization -Identity "<OBJECT ID>" -Resource "<a staff address>"

InScope should be True for a staff address and False for anyone outside the group. Then use Check connection on the card.

What this permission allows: Microsoft has no add-only permission, so the role technically covers reading and changing mail in the mailboxes in your group. ThouShaltNotClick only ever creates the simulation message in the Inbox. It can't send mail, gets no directory access, and can't touch any mailbox outside the group. Exchange Online enforces that, not just our software. You can remove the role assignment, the scope and the app at any time; email us and we'll send the exact commands.

Questions

Do we still need to allowlist your sending domains?+
Not for simulations: they never pass your spam filter. You may still want to allowlist thoushaltnotclick.com so our invitations and training emails reach your staff.
Who receives simulations?+
Only the staff you add to ThouShaltNotClick, and only at addresses on the email domains your school has verified with us.
Can you read our email?+
With Google, no: the permission only adds messages. With Microsoft, the role technically allows it for the mailboxes in your group, and we never do; we only create the simulation message.
We use both Google and Microsoft. Which one?+
Set up the one that hosts your staff mailboxes. If some staff are on each, set up both.

Need a hand? Email support@thoushaltnotclick.com and we'll walk your administrator through it.

← Previous
Sim senders & key staff
Next β†’
Phishing campaigns