Enable Phishing Simulations
ThouShaltNotClick places phishing simulations straight into your staff's inboxes. Your Google Workspace or Microsoft 365 administrator gives us one narrow permission to do that, once. Until it's done, simulations can't reach your staff.
Google Workspace
You need a Google Workspace super admin. It takes about two minutes.
- In ThouShaltNotClick, open Integrations β Enable Phishing Simulations and choose Google Workspace. Keep the Client ID and the OAuth scope handy; each has a Copy button.
- In the Google Admin console, go to Security β Access and data control β API controls β Manage Domain Wide Delegation. The card links straight there.
- Click Add new, paste the Client ID and the scope, and click Authorize. The scope is exactly
https://www.googleapis.com/auth/gmail.insert. - Back on the card, type a staff email address under Check connection. No email is sent. It usually takes effect within a few minutes; if the check says it isn't ready, try again a little later.
What this permission allows: adding a message to a mailbox. It can't read, search, send or delete anything. To remove it, delete the entry on the same Domain Wide Delegation page.
Microsoft 365
You need an Exchange Online administrator who can run PowerShell. Access is limited to the mailboxes you choose, through Exchange Online RBAC for Applications.
Use the App ID shown on Integrations β Enable Phishing Simulations (Microsoft 365 tab) wherever the commands say <APP ID>. Put the staff who should receive simulations in a mail-enabled security group first.
1. Add the app to your tenant, with no permissions
Microsoft Graph PowerShell:
Connect-MgGraph -Scopes "Application.ReadWrite.All"
$sp = New-MgServicePrincipal -AppId "<APP ID>"
$sp.Id # the app's Object ID in your tenant2. Give it access to your staff group's mailboxes only
Exchange Online PowerShell. Replace the group's distinguished name and the Object ID from step 1:
Connect-ExchangeOnline
New-ServicePrincipal -AppId "<APP ID>" -ObjectId "<OBJECT ID>" -DisplayName "ThouShaltNotClick Practice Emails"
New-ManagementScope -Name "TSNC simulations" -RecipientRestrictionFilter "MemberOfGroup -eq '<GROUP DN>'"
New-ManagementRoleAssignment -App "<OBJECT ID>" -Role "Application Mail.ReadWrite" -CustomResourceScope "TSNC simulations"3. Check it
Changes take 30 minutes to 2 hours to apply. Then:
Test-ServicePrincipalAuthorization -Identity "<OBJECT ID>" -Resource "<a staff address>"InScope should be True for a staff address and False for anyone outside the group. Then use Check connection on the card.
What this permission allows: Microsoft has no add-only permission, so the role technically covers reading and changing mail in the mailboxes in your group. ThouShaltNotClick only ever creates the simulation message in the Inbox. It can't send mail, gets no directory access, and can't touch any mailbox outside the group. Exchange Online enforces that, not just our software. You can remove the role assignment, the scope and the app at any time; email us and we'll send the exact commands.
Questions
Do we still need to allowlist your sending domains?+
Who receives simulations?+
Can you read our email?+
We use both Google and Microsoft. Which one?+
Need a hand? Email support@thoushaltnotclick.com and we'll walk your administrator through it.