As a core component of the Crux Root Phishing Simulation Platform, this add-in allows your employees to report suspicious emails with a single click. This enables you to accurately measure and track your simulation results.
Method 1: Centralized Deployment (For IT Administrators)
This is the recommended method for automatically deploying the add-in to all employees or specific departments. It requires Microsoft 365 Admin privileges.
- Access M365 Admin Center: Go to admin.microsoft.com.
- Navigation: From the left-hand menu, go to Settings > Integrated Apps.
- Upload App: Click the Upload custom apps button.
- App Type: In the panel, select “Office Add-in” as the app type.
- Upload Manifest: Select the “Upload manifest file (.xml) from device” option and upload the provided cruxroot_outlook-plugin.xml file.
- User Assignment: Choose the scope of the deployment (Entire organization, specific groups, or designated test users).
- Deployment: Click “Deploy” to complete the process.
Note: It may take up to 24 hours for the add-in to appear in the Outlook Ribbon for all users, depending on Microsoft’s synchronization cycles.
Method 2: Individual Installation (Testing and Manual Setup)
In scenarios where centralized deployment is not utilized, users can manually add the add-in to their own accounts.
- Quick Access: While logged into your Outlook Web account, navigate directly to aka.ms/olksideload.
- Tab Selection: On the Outlook Add-ins page, click the My Add-ins tab.
- Custom Add-in: Scroll to the bottom of the page and select Add a custom add-in > Add from file….
- File Selection: Choose the cruxroot_outlook-plugin.xml file provided to you and confirm the installation.
How to Use the Add-in?
Once installed, reporting a suspicious email takes only a few seconds:
- Step 1: While viewing a suspicious email, click the “Phish Report” (Crux Root) button in the Outlook toolbar.
- Step 2: In the side panel that appears on the right, click the “Reported Phishing” button.
- Step 3 (Result): If the reported email is a Crux Root simulation, the system will display a “Thank You” message and record the successful report in the dashboard.
Technical Requirements and Security
| Feature | Detail |
| Supported Platforms | Outlook 2016+, Outlook Web (OWA), Outlook for Mac, iOS, and Android. |
| Security (SSL) | All communications are end-to-end encrypted via HTTPS. |
| Data Privacy | The add-in only transmits reported email metadata to your organization’s private dashboard. |
| Integration | Fully compliant with the Microsoft 365 standard add-in architecture (Office.js). |

