Managed Security Awareness Training and Phishing Simulation
Managed Security Awareness Training and Phishing Simulation is a recurring program run on Microsoft Attack Simulation Training in Defender for Office 365: IT Partner designs and executes monthly phishing simulations, assigns micro-training to the users who need it, enrolls new hires automatically, and delivers quarterly reports formatted for cyber insurers and auditors. The service costs $375 per tenant per month for the program platform, setup, and reporting, plus $3 per enrolled user per month, with no long-term contract. It requires Microsoft 365 E5 or Defender for Office 365 Plan 2 licensing for enrolled users, and it is the continuous counterpart to IT Partner's one-time Phishing Attack Simulation engagement.
What this engagement is
A phishing test you ran once, eighteen months ago, proves almost nothing — to your insurer, your auditor, or yourself. What changes user behavior, and what renewal questionnaires increasingly ask for, is a continuous program: regular simulations, training assigned to the people who actually clicked, coverage of new hires before attackers find them, and reporting that shows the trend. That is what this service operates for you, and it does so on the platform you may already license — Microsoft Attack Simulation Training in Defender for Office 365 — rather than on a third-party tool that adds another vendor, another agent, and another data processor to your estate. Each month, IT Partner plans and launches a simulation campaign using varied, current techniques (credential harvesting, malicious attachments, link-based lures, OAuth consent tricks, and similar patterns as the threat landscape shifts), reviews the results, and lets the platform assign short, targeted training modules to users who fell for the lure. New employees enter a dedicated onboarding stream so day-30 hires are not your softest target. Every quarter you receive a report deliberately formatted for the audiences that ask for it — insurance renewals, compliance audits, and leadership — with participation, click and compromise rates, training completion, and trend lines. The program is priced in two parts, month to month: $375 per tenant per month, which covers the program itself — tenant setup and upkeep of Attack Simulation Training, campaign design, the new-hire stream, and the monthly and quarterly reporting — plus $3 per enrolled user per month for each person simulated and trained. The scope boundary is explicit: this is the recurring program. A one-time, deeply customized simulation exercise is a separate IT Partner service, and remediating your broader email security posture is separate work we will point you to honestly when the data says you need it.
Success criteria
What you receive
How the work unfolds
Verify that enrolled users carry the required Microsoft 365 E5 or Defender for Office 365 Plan 2 licensing, configure Attack Simulation Training in your tenant, agree the simulation scope and communication approach with your leadership, send the launch communication, and run the baseline campaign that sets your starting metrics.
Each month IT Partner designs the campaign — technique, lure theme, target groups — launches it, monitors delivery, and reviews results. Techniques rotate deliberately: credential harvest one month, attachment or OAuth-consent patterns another, so the program measures vigilance rather than memory of a single template.
Users who fail a simulation are automatically assigned short, relevant training modules, with due dates and reminders. Completion is tracked; persistent non-completion is escalated to your named contact rather than silently ignored, because incomplete training is exactly what an auditor will find.
New users are enrolled automatically into a starter path — baseline simulation plus foundational training — so awareness coverage does not depend on someone remembering to add them.
Every quarter you receive the evidence report: participation, click and compromise rates, repeat-clicker analysis, training completion, and trend against prior quarters, formatted for insurers and auditors. The quarterly review is also where we tune the program — and where we tell you plainly if the data points to gaps that awareness training cannot close, such as missing email authentication or weak Defender policies.
Prerequisites
Who does what
IT Partner
- Configure and operate Attack Simulation Training for the program.
- Design, schedule, launch, and review the monthly simulation campaigns.
- Manage training assignment rules, track completion, and escalate persistent non-completion.
- Operate the new-hire enrollment stream.
- Deliver monthly summaries and quarterly insurer-and-auditor-ready reports.
- Recommend program adjustments and flag posture problems the data reveals, with honest routing to the right follow-on service.
Your team
- Maintain the required licensing for enrolled users and tell us about major workforce changes.
- Approve the simulation scope, communication plan, and any scheduling constraints.
- Handle employment-side matters: HR policy alignment, works-council or legal consultation where applicable, and any internal consequences framework for repeat clickers.
- Reinforce training completion internally when we escalate non-completion.
- Review quarterly reports and decide on recommended follow-on actions.
What's not included
Limitations & technical notes
Frequently asked questions
What is the Managed Security Awareness Training and Phishing Simulation service?
It is a recurring, fully managed program that IT Partner operates on Microsoft Attack Simulation Training in Defender for Office 365: monthly phishing simulations with rotating techniques, automatic micro-training for users who fail, an automatic onboarding stream for new hires, and quarterly reports formatted for cyber insurers and auditors. It costs $375 per tenant per month plus $3 per enrolled user per month, with no long-term commitment.
Who is this program for?
Small and mid-size organizations that need continuous, evidenced security awareness training — most commonly because a cyber insurance renewal, a compliance framework, or a customer audit asked for proof of regular phishing simulations and training completion, and a once-a-year test no longer answers the question.
How is this different from IT Partner's one-time Phishing Attack Simulation service?
The one-time engagement is a project: up to three deeply customized payloads built for your environment, executed within a month, with a findings report — excellent as a baseline or an annual red-team-style exercise. This service is the ongoing program: a campaign every month, training follow-through, new-hire coverage, and quarterly evidence reporting, billed monthly per tenant plus per enrolled user. Many clients run the one-time simulation first and roll its results into this program's first quarterly report.
What licensing do we need?
Microsoft requires Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 for users included in Attack Simulation Training — and the license is needed by every simulated user, not just the administrator. Note that Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, which is not sufficient for this feature; Plan 2 is available as an add-on. We verify licensing during onboarding and flag exactly who is covered before anything launches.
What actually happens each month?
IT Partner designs that month's campaign — technique, lure theme, and target groups — launches it through Attack Simulation Training, monitors delivery, and reviews the results. Users who click or submit credentials get training assigned automatically. Your named contact receives a monthly summary; every third month it rolls up into the quarterly evidence report.
What happens when an employee clicks a simulated phish?
Nothing punitive from our side: the user lands on a teachable moment and is automatically assigned a short, relevant training module with a due date and reminders. Results reach your contact in aggregate, with repeat-clicker patterns identified so you can decide how to handle them under your own HR policy — that consequences framework is deliberately yours, not ours.
What is in the quarterly report?
The evidence insurers and auditors actually request: simulation cadence and coverage, click and compromise rates by campaign and technique, training assignment and completion rates, repeat-clicker analysis, new-hire coverage, and quarter-over-quarter trends — presented so it can be attached to a renewal questionnaire or shown to a board without rework.
How are new hires handled?
Automatically. New users are enrolled into an onboarding stream — a baseline simulation plus foundational training — without anyone filing a request. New employees are a favorite phishing target precisely because they do not yet know what internal email looks like, so the program covers them by default rather than by memory.
Why build on Microsoft's platform instead of KnowBe4 or another third-party tool?
Three practical reasons: the capability is already in licensing many organizations own (E5 or Defender for Office 365 Plan 2), it runs natively inside your tenant with no additional vendor processing your employee data, and results integrate with the Microsoft security stack you already operate. If your organization is committed to a third-party platform, this particular service is not the fit — we scope it honestly rather than manage a tool it is not built for.
How does pricing and billing work?
Two components, both monthly. A $375 per tenant per month program fee covers the platform side — configuring and maintaining Attack Simulation Training in your tenant, designing and launching each month's campaign, running the new-hire stream, and producing the monthly summaries and quarterly evidence reports. On top of that, $3 per enrolled user per month covers each person simulated and trained — the users included in the program that month are the users billed. As a worked example, a 100-user organization pays $375 + $300 = $675 per month. Program setup in the first cycle is covered by the tenant fee rather than billed as a separate onboarding charge. It is a month-to-month service with no long-term contract: you can stop at any time, and all we ask is payment of previously approved invoices.
Will simulations disrupt the business or embarrass employees?
The program is designed to build a reporting culture, not a fear culture. Campaigns respect the freeze periods and sensitive-team exclusions you set, individual results are handled through automatic training rather than public callouts, and communications templates for launch are part of onboarding so employees hear about the program from leadership, not from a lure.
Can campaigns be customized to look like our internal systems?
Campaigns are tailored within the program — lure themes, targeting, difficulty, and timing are adjusted to your organization, and techniques rotate monthly. Bespoke payload engineering that deeply mimics your internal applications is the province of the one-time Phishing Attack Simulation engagement, which exists precisely for that depth and pairs well with this program as an annual exercise.
Will this satisfy our cyber insurance requirements?
The program is built around what insurers commonly ask for — regular simulations, measured completion, documented cadence, and trend evidence — and the quarterly report is formatted to answer those questionnaires directly. But no service provider can honestly guarantee an underwriting outcome: insurers differ, and the decision is theirs. What we ensure is that when the question arrives, you have real evidence instead of a scramble.
What if the program reveals a real security problem?
We tell you, in plain terms, in the monthly summary or quarterly review — for example, if failure patterns suggest weak email authentication or missing Defender policies, or if a real incident surfaces during the program. Fixing those problems is separate, honestly scoped work: email security hardening for posture gaps, and the Managed Detection and Response service if you need continuous monitoring and response behind the training layer.
How fast can the program start?
The first monthly cycle covers onboarding end to end: licensing verification, tenant configuration, scope and communications sign-off, and the baseline campaign. From the second cycle the program is in steady state. The main schedule dependency is your side's sign-off on scope and communications — the technical setup is rarely the long pole.