---
title: Defender for Email Impersonation Allowance
description: This guide will show an administrator how to create an impersonation exception for a specified address or domain for an Anti-Phishing policy.
---

[Skip to content](https://knowledge.sittadel.com/defender-for-email-impersonation-allowance#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en)
3. [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)

# Defender for Email Impersonation Allowance

## This guide will show an administrator how to create an impersonation exception for a specified address or domain for an Anti-Phishing policy.

### **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-04-16-2156-PM.png?width=125&height=133&name=image-png-Jan-19-2024-04-04-16-2156-PM.png)Role Requirements**

Procedure Scope: **Administrators**

Required Group Membership: **Admin.Security**

**![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-29-09-3760-PM.png?width=670&height=5&name=image-png-Jan-19-2024-04-29-09-3760-PM.png)**

**Defender Email Impersonation Sender Allowance**

1. Navigate to the [Anti-Phishing – Microsoft Defender](https://security.microsoft.com/antiphishing) portal, locate and select the **Security Essentials Anti-Phishing** **Policy** or the **Equivalent Existing Custom Anti-Phishing Threat Policy**. A flyout will be displayed showing all applicable security settings, locate the **Phishing threshold & protection** section and select the **Edit** action to begin the exception process.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Dec-04-2024-04-03-02-3466-PM.png?width=670&height=356&name=image-png-Dec-04-2024-04-03-02-3466-PM.png)
2. From the **Protection settings** section we will want to select the **Manage trusted sender(s) and domain(s)** prompt under the **Add trusted senders and domains** subsection.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Dec-04-2024-04-09-49-6218-PM.png?width=670&height=356&name=image-png-Dec-04-2024-04-09-49-6218-PM.png)
3. Under the manage prompt we can select either the **Sender** or **Domain** header followed by selecting the **Add senders** or **Add domains** action.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Dec-04-2024-04-12-47-3364-PM.png?width=670&height=356&name=image-png-Dec-04-2024-04-12-47-3364-PM.png)
4. Here we will be able to utilize the text field under the **Email** section to supply the desired **address** or **domain** associated with the account we wish to allow the impersonation protection for. To finalize the **address** or **domain** addition select **Add** to generate the entry to the list below, if it is propagating select **Add** to continue.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Dec-04-2024-04-13-01-1249-PM.png?width=670&height=356&name=image-png-Dec-04-2024-04-13-01-1249-PM.png)
5. You will return to the previous section, here we will want to verify that are previous addition is properly generating in the list, if the entry is there we will want to select **Done** to continue.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Dec-04-2024-04-13-52-3355-PM.png?width=670&height=356&name=image-png-Dec-04-2024-04-13-52-3355-PM.png)
6. We will return back to the **Edit** page, their should be an incremental change to the **Manage # of trusted sender(s) and domain(s)** prompt, if the changes have been reflected here. Select **Save** to finalize the impersonation allowance process.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Dec-04-2024-04-13-58-0220-PM.png?width=670&height=356&name=image-png-Dec-04-2024-04-13-58-0220-PM.png)

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>