Configure Symbol Report a Phish Button (Outlook)

The Symbol Security "Report a Phish" Outlook Add-In allows your users to report suspicious emails with a single click. Follow this guide to install or update the add-in using Microsoft 365.

Deployment Steps

Step 1 - Access the Microsoft 365 Admin Center

Log into your Microsoft 365 Admin account and access the Admin Center from your list of available apps.

Group 162

Some styles on the screens can vary depending on the version of the Admin Center you have

Step 2 - Navigate to Integrated Apps

From the left sidebar, navigate to Settings > Integrated Apps.

🚨 Important Upgrade Notice: If you have an older version of the Report a Phish button installed, click on it in the apps list, select Remove app, and complete the deletion before proceeding. We also highly recommend advising users to clear their browser and Outlook caches to prevent display issues.

To remove an existing app click on the app name and follow these steps:
remove_add_in

Step 3 - Upload the Manifest File

image (4)

First, obtain your custom XML manifest file from your Symbol Portal:

  • For specific companies: Go to your Company Settings, locate the Report a Phish section, and click Download Manifest.
  • For MSPs/vCISOs: To deploy globally, download the manifest from your main Account Settings.

Next, upload it in Microsoft 365:

  1. From the Integrated Apps view, click Upload custom apps.
  2. Select Office Add-in as the app type.
  3. Choose Upload manifest file (.xml) from device, select your downloaded XML file, and click Next once validated.
image (5)

Step 4 - Assign Users and Deploy

  • Choose who can access the app: Entire Organization, Specific users/groups, or Just you (for testing).
Assign Users
  • Accept the initial Microsoft permissions request and click Next.
Accept Permissions Requests
  • Review your configuration and click Finish Deployment. It can take up to 24 hours for the button to appear in users’ Outlook clients.
Review and finish deployment

V2 Upgrade & Authentication Requirements

If you are upgrading from a previous version of the Report a Phish button to Version 2 (V2), please note the following:

  • Clean Installation Required: To avoid receiving a deprecation or error message when reporting emails, administrators must fully remove the old add-in (as described in Step 2) before uploading the new V2 XML manifest.
  • One-Time End-User Authentication: To comply with modern Microsoft security requirements, the first time users click the new V2 button, they will be prompted to log into Outlook and grant Symbol permission to access their mailbox headers. This is a secure, one-time action required to activate the button.
  • Admin Consent Check: If your organization restricts users from granting permissions to third-party integrations, an IT administrator will need to approve the request globally under Azure Portal > Enterprise Applications > Admin consent requests.

For further information about this new experience, review:Symbol Report a Phish Button (v2 Experience)