First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft partner since 2006 1,100+ organizations under management
Home/Blog/Train users against phishing with Microsoft Defe…

Train users against phishing with Microsoft Defender for Office 365 Attack simulation training

2026-06-16·IT PartnerMicrosoft 365modern securitySecurityCloud Security

Phishing, credential theft, malicious links, and consent-based attacks remain everyday risks for Microsoft 365 organizations. Microsoft Defender for Office 365 Attack simulation training helps you safely test how users respond, assign targeted training, and improve resilience before a real attacker succeeds.

Why simulated phishing still matters in 2026

Technical controls such as Microsoft Defender for Office 365, Microsoft Defender XDR, Microsoft Entra ID Conditional Access, and phishing-resistant MFA are essential, but users are still targeted by realistic social engineering. Attack simulation training lets you run controlled campaigns inside your Microsoft 365 tenant, measure susceptibility, and provide training based on user behavior.

The goal is not to embarrass users. A mature program uses simulations to identify process gaps, improve reporting habits, tune security policies, and reinforce safer behavior over time.

Attack simulation training is not the same as penetration testing

The original version of this article discussed penetration testing and Attack simulation training together. They are related to security validation, but they are different activities.

Attack simulation training is a Microsoft Defender for Office 365 capability focused on user awareness and phishing readiness. It sends safe simulated messages and tracks user actions such as opening a message, clicking a link, entering credentials on a mock landing page, or reporting the message.

Penetration testing is a broader security assessment that may test applications, infrastructure, identities, and cloud configurations. If you plan penetration testing in Microsoft cloud environments, review Microsoft’s current Cloud Penetration Testing Rules of Engagement: https://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing.

Licensing and prerequisites

Attack simulation training is available with Microsoft Defender for Office 365 Plan 2 and suites or add-ons that include Plan 2, such as Microsoft 365 E5, Office 365 E5, and eligible Microsoft 365 E5 Security add-on licensing. It is not included in Exchange Online Protection or Defender for Office 365 Plan 1 by itself. Microsoft 365 Business Premium includes strong SMB security capabilities, but organizations that want Attack simulation training typically need to add Defender for Office 365 Plan 2 or an eligible suite/add-on.

For CSP customers, confirm the correct Microsoft 365 or security subscription under the current New Commerce Experience (NCE) model and assign licenses to the users who will be included in simulations and training. Microsoft licensing and service availability can change, so validate your tenant’s entitlement before rollout.

Administrators should use least-privileged roles where possible, such as Attack Simulation Administrator and Attack Payload Author, instead of relying on Global Administrator for day-to-day operations.

What Attack simulation training can do

In the Microsoft Defender portal at https://security.microsoft.com, Attack simulation training helps you create and manage phishing readiness campaigns. Current capabilities include:

  • Creating one-time simulations or using simulation automations for recurring campaigns.
  • Selecting Microsoft-provided payloads or creating tenant-specific payloads.
  • Using payload automations to keep campaigns fresh and realistic.
  • Choosing landing pages and end-user notifications.
  • Assigning training automatically to users who fall for a simulation.
  • Tracking results, repeat susceptibility, training completion, and reporting behavior.
  • Using results to improve Defender for Office 365 policies, user-reported phishing workflows, and security awareness plans.

Microsoft Learn documentation for getting started is available here: https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-get-started.

Common simulation techniques

Available techniques can vary as Microsoft updates the service, but Attack simulation training commonly supports scenarios such as:

  • Credential harvest: users are directed to a realistic but safe sign-in page to test whether they would submit credentials.
  • Malware attachment: users receive a simulated malicious attachment to test risky attachment behavior.
  • Link in attachment: a document contains a link that leads to the simulated phishing flow.
  • Link to malware: users are encouraged to click a link that represents a malicious download path, without delivering real malware.
  • Drive-by URL: users are directed to a simulated site representing a browser-based compromise path.
  • OAuth consent grant: users are prompted to grant permissions to a simulated malicious app, reflecting a real-world consent phishing technique.

Use Microsoft’s current documentation when selecting payloads and techniques: https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-payloads.

How to launch a simulation

To launch a simulation, open the Microsoft Defender portal at https://security.microsoft.com and go to Email & collaboration > Attack simulation training > Simulations. You can also use the direct entry point when available: https://security.microsoft.com/attacksimulator.

A typical setup includes:

  1. Select Launch a simulation.
  2. Choose a social engineering technique.
  3. Select or create a payload.
  4. Define target users or groups.
  5. Configure landing pages, end-user notifications, and training assignments.
  6. Schedule the simulation or launch it immediately.
  7. Review reports and follow up with training, policy tuning, and user communication.

For most organizations, it is better to start with a pilot group, validate routing and reporting, and then expand to broader departments or all users.

Best practices for SMB and CSP customers

A successful phishing simulation program should be planned like a security improvement initiative, not a one-time test.

Recommended practices:

  • Get leadership and HR approval before the first campaign.
  • Start with a pilot group that includes IT, security, and business stakeholders.
  • Avoid punitive messaging; focus on coaching and safer behavior.
  • Exclude or handle special mailboxes carefully, such as help desk queues, SOC mailboxes, journaling mailboxes, and automated processing accounts.
  • Define success metrics before launch: report rate, click rate, credential submission rate, training completion, and repeat susceptibility.
  • Run recurring campaigns with varied payloads instead of one predictable annual test.
  • Pair simulations with clear reporting instructions, such as the built-in Microsoft Report button or Report Message/Report Phishing workflow.
  • Use results to improve mail policies, Safe Links, Safe Attachments, anti-phishing policies, user training, and executive protection.

Connect simulation results to your broader Microsoft security program

Attack simulation training is most valuable when it is connected to the rest of your Microsoft security stack. Use campaign results to validate and improve:

  • Microsoft Defender for Office 365 policies for phishing, impersonation, Safe Links, Safe Attachments, and user submissions.
  • Microsoft Defender XDR investigation and response workflows.
  • Microsoft Secure Score recommendations related to email, identity, and endpoint security.
  • Microsoft Entra ID controls such as Conditional Access, authentication strength, risk-based access, and phishing-resistant MFA or passkeys.
  • Security awareness training and onboarding for new employees.

The strongest programs combine user education, modern identity protection, secure email configuration, endpoint protection, and continuous monitoring.

Key takeaways

  • Attack simulation training remains a current Microsoft Defender for Office 365 Plan 2 capability for testing phishing readiness and assigning targeted training.
  • Use the Microsoft Defender portal and current Microsoft Learn documentation; older Microsoft 365 Defender and docs.microsoft.com references should be retired.
  • Do not confuse simulated phishing with penetration testing; penetration testing has separate scope, approvals, and Microsoft Cloud Rules of Engagement.
  • For CSP customers, confirm Defender for Office 365 Plan 2 or eligible E5/E5 Security licensing under the current NCE subscription model.
  • The best results come from recurring, non-punitive campaigns tied to reporting workflows, Defender for Office 365 tuning, Entra ID protections, and measurable improvement.

Need help building a practical phishing-resilience program? IT Partner can review your Microsoft 365 licensing, configure Microsoft Defender for Office 365 Attack simulation training, tune email protection policies, and connect results to Microsoft Defender XDR and Microsoft Entra ID security controls.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.