“Hi there, I have question related to single sign on for Knowbe4. Currently we are creating user manually. My plan is to enable single sign on using Entra id which is outlook email and password of user.”
“The problem we've been having recently is that Microsoft Defender is flagging the attachments on KnowBe4 phishing emails as malicious. This would be great if they were actual phishing attempts, but because the file is being flagged and quarantined, the user is NOT getting flagged in KnowBe4 as having failed the test when they try to open the attachment.”
“Our company has been using their products for 3 years. We have had great success, our users are more security conscious and aware on how to spot and report phishing emails.”
“The thought was if someone was inside knowbe4 and managed to burrow into systems, they could work from inside the mailsystem. Given that this guy got caught shortly after receiving his laptop, I don't think he was going to embedding himself in much.”
“KnowBe4's mailserver is pretty much set up where you can't weaponize it. Plus, they'd have a hard time bypassing email protection software, as they wouldn't be sending from the same hostname or same IPs as KB4 does.”
“Since no one responded correctly here, in the blog post from KnowBe4 they said it was AI enhanced, not generated. They took a stock image of a guy in glasses and used AI to modify it with an actual photo of the interviewee.”
“The article is incorrect. The blog post from KnowBe4 is here: [https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us](https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us)”
“Reach out to KnowBe4 support. They have 24 root domains that need to be added to your tenant so MS trusts the emails and doesn't inadvertently 'click' the email on scans, generating a false positive.”
“It seems like Advanced Delivery Policies work pretty well at stopping these false positives, but if not then the Smart Hosting setup should definitely take care of it. On-premises the smart host config will probably be your only effective option, though I haven't messed with On-premises exchange for 3 or 4 years now.”
“We've recently implemented KnowBe4 and started our first internal Phishing tests. Now is the problem, that as soon as the E-Mail arrives it is being marked as read and clicked. I've tried disabling my local anti virus, disabling every Outlook add-in but still haven't found a fix.”
“We had a user plausibly refute a reported click on a phishing simulation, and found out the IP of origin for the click belongs to Microsoft. We have all KB4 domains/IPs whitelisted in 365.”
“I am a little late to this post however they do NOT spoof the domain; you can clearly see it comes from knowbe4.com in the email header and all they do is modify the From Address to say something else. All you need to do is set up a rule in Outlook that looks for this and route it to a folder that you never open emails from.”
“Not PAB, but my concern with Phisher is that an email containing PHI could be sent to knowbe4 unencrypted. I'm not sure if it encrypts the copy it sends them or not.”
“I'm of the opinion that the best value you can get from a service like knowbe4 would be from refusing to whitelist them and telling them to get through your filters...”
“Knowbe4 is absolute trash. Some of their *correct* answers are the opposite of what you should do. I ended up thinking what the best answer was, to looking for the one that the test wanted.”
“We have had Knowbe4 for 2 years. I like it but management has only allowed us to run 1 training campaign. They don't want to inconvenience users too much with training.”
“Ever spoken to knowbe4 sales? they will hound you, call your personal number(and get it from fuck knows where), tell your boss you suck if you don't agree to whatever upgrade theyre shilling etc, utterly horrid company to do any business with”
“Seems like the post over the last little while have been people either switching because of the price or have already switched awhile ago. Have notice that the training hasn't been updating in some time or atleast very little update.”
“We've been with KnowBe4 for years and whilst it has every feature under the sun, we're finding it a bit stale now so we're looking at others but can't find a decent replacement. We've had demos from;”
“It is intended to get the email in front of the user. It is designed to evaluate the end user's ability to recognize a suspicious communication and respond accordingly.”
“I've just set up KnowBe4 and at no point did they ask to spoof our domain, but they did ask to whitelist the phishing domains in M365 to ensure they got through. And we all know M365 regularly lets spam through so I personally have no issues with this.”
“So you pay for a service that you and Knowbe4 setup together, and then you want to undo those changes? I'd get it if it was for part of a pen test but that isn't what this is.”