Review user-reported emails
Arctic Wolf Managed Security Awareness® (MA) Portal administrators can review emails that were reported using the Report Email button.
These actions are required:
- Obtain these Microsoft Entra ID credentials used when you configured the Report Email button:
Tip:
For more information about the Report Email button for Outlook, see Configure the Report Email button for Microsoft 365.
- Application (client) ID
- Directory (tenant) ID
- Client Secret value
Note:
This is the Client Secret value that you created when configuring the Report Email button, not the secret ID found in Microsoft Entra ID settings.
- Obtain these details from the email you want to review:
- The email address that reported the email.
- The Graph Message ID for the message.
For more information about copying a Graph Message ID, see Track a suspicious email using a Graph Message ID.
Note:If the email is moved to another folder, the Graph Message ID changes and the ID from the Reported Emails tab is no longer valid.
Download the file
Retrieve the message
Based on your environment, retrieve the message using one of these CLI options: