How to set up DED for Microsoft 365
Direct Email Delivery injects the simulation email directly into the Inbox of targeted users in Outlook.
Overview
DED sending limitations
Emails will not be delivered to:
- Users who are not part of your Microsoft tenant.
- Guest users in your Microsoft tenant (e.g. @outlook.com, or any user whose mailbox is not hosted on your Microsoft tenant)
- Aliased addresses using β+β (e.g. name+alias@wizer-training.com)
If your organization is unable to use Direct Email Delivery due to technical, policy, or any restriction, phishing simulation emails can still be delivered by configuring Microsoft 365 whitelisting.
You can see our guide here β Microsoft 365 Whitelisting
How to connect?
Step 1:
While in the Wizer admin console Phishing simulation tab, press on the Phishing simulation settings option:
Step 2:
Once in the settings tab select Direct Email Delivery, expand the Microsoft DED tab and press "Connect":
Step 3:
Upon pressing connect, you will be redirected to the Microsoft Oauth page to choose the account
Select the account with the admin access level: 
Step 4:
Please review the permissions requested by the app and press Accept to finish the setup:
Once the above is done, you will be redirected back to the Wizer admin console.
Why We Ask
To safely deliver simulated phishing emails directly into user inboxes via the Microsoft Graph API and verify our connection during setup.
What They Are Limited To
- Authentication: Uses your Client ID and Secret to exchange for a short-lived access token. This token acts as a temporary key, strictly restricted to the specific Graph API permissions granted in your tenant.
- Connection Check: Briefly reads high-level tenant info solely to confirm the integration is working.
- Direct Email Delivery: Operates as write-only to insert simulation emails into recipient inboxesβit cannot read, search, modify, or delete existing emails.
Upon successful connection you should see the following screen:
After DED is connected you should be all set.
Yet if you wish, you can test the email delivery by running a one-time campaign as described here.