False Positive — Phishing Detection Dispute & Training Waiver Request

Nsigtic 20 Reputation points
2026-08-25T16:28:00.2533333+00:00

I am writing to request support for formally dispute a phishing/whaling detection flag that has been applied to company account so that I can request that the associated training requirement be waived.

What Occurred:

Today 08/25/2026, I received a suspicious email that I identified as a potential phishing and/or whaling attempt. I took the following actions in response:

  1. I did NOT open or click any links within the email.
  2. I reported the email as phishing using the appropriate reporting mechanism.
  3. I forwarded the phishing attempt to Netflix (the impersonated entity), which is consistent with best practices for reporting phishing attempts targeting external brands.

These are precisely the actions employees are trained and expected to take when they suspect a phishing attempt.

My Concern:

I have since been notified that I "fell prey" to a phishing/whaling attempt and have been assigned mandatory security awareness training. I strongly believe this is a false positive detection. If the system's detection is based solely on whether a link URL was accessed — and not by me or any company device — this may indicate that a third-party security scanner (e.g., email gateway, URL reputation service, or link preview system) triggered the detection, not any action on my part.

My Request:

I respectfully request that the Security team:

  1. Review the detection logs to confirm whether the link was accessed by me/a company device, or by an automated system or external scanner.
  2. Clear the false positive flag from my account if it is confirmed that I did not open the link.
  3. Waive the mandatory phishing training requirement, given that my behavior was fully compliant with security policies.

I take cybersecurity seriously and acted in good faith and in full accordance with phishing response expectations. I am happy to provide any additional information or documentation to assist with your review.

Outlook | Web | Outlook on the web for business | Security
0 comments No comments

Answer accepted by question author
Kai-L 18,725 Reputation points Microsoft External Staff Moderator
2026-08-25T17:01:56.7933333+00:00

Dear Nsigtic,

Not opening the links and reporting the message were the right calls, so thank you for acting quickly. However, this needs to go to your own organization rather than the forum. What you are describing, a notification that you fell for the attempt with training assigned automatically, is typical of a simulated phishing exercise run internally. If that is the case, the flag, the logs and the training assignment all sit inside your company's own tooling, and only your IT or security team can review or clear them. We have no visibility into your organization's configuration from a public forum.

One thing worth raising with them: forwarding the message to the impersonated brand is generally not advised, and it may be relevant here. Simulated phishing messages contain a unique tracking link, so if any automated scanner on the receiving side followed it, that could register as a click even though you never opened it yourself. That is worth mentioning when you ask them to check the logs, as it may be exactly what they find.

I would suggest sending the same summary you posted here directly to your IT or security team, as it is clear and well documented. If you are not sure who to contact, this article can help: How do I find my Microsoft 365 admin?

If they need help interpreting the detection logs or confirming whether the link was opened by an automated scanner rather than by you, they can raise a service request with Microsoft from the Microsoft 365 admin center. Details are here: Get support - Microsoft 365 admin

I hope this information is helpful and provide you with a clear path forward. Should you have any further questions or need additional assistance, please don't hesitate to reach out. I'm always happy to help. Have a wonderful day! 


If the answer is helpful, please click "Yes" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  

Note: Please follow the steps in the forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread.  

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.