First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Managed Security Awareness Training and Phishing Simulation
Managed ServicesSecurity and Protection

Managed Security Awareness Training and Phishing Simulation

Managed Security Awareness Training and Phishing Simulation is a recurring program run on Microsoft Attack Simulation Training in Defender for Office 365: IT Partner designs and executes monthly phishing simulations, assigns micro-training to the users who need it, enrolls new hires automatically, and delivers quarterly reports formatted for cyber insurers and auditors. The service costs $375 per tenant per month for the program platform, setup, and reporting, plus $3 per enrolled user per month, with no long-term contract. It requires Microsoft 365 E5 or Defender for Office 365 Plan 2 licensing for enrolled users, and it is the continuous counterpart to IT Partner's one-time Phishing Attack Simulation engagement.

Timeline 30 daysService owner Roman SotnikMicrosoft Defender for Office 365Microsoft 365

What this engagement is

A phishing test you ran once, eighteen months ago, proves almost nothing — to your insurer, your auditor, or yourself. What changes user behavior, and what renewal questionnaires increasingly ask for, is a continuous program: regular simulations, training assigned to the people who actually clicked, coverage of new hires before attackers find them, and reporting that shows the trend. That is what this service operates for you, and it does so on the platform you may already license — Microsoft Attack Simulation Training in Defender for Office 365 — rather than on a third-party tool that adds another vendor, another agent, and another data processor to your estate. Each month, IT Partner plans and launches a simulation campaign using varied, current techniques (credential harvesting, malicious attachments, link-based lures, OAuth consent tricks, and similar patterns as the threat landscape shifts), reviews the results, and lets the platform assign short, targeted training modules to users who fell for the lure. New employees enter a dedicated onboarding stream so day-30 hires are not your softest target. Every quarter you receive a report deliberately formatted for the audiences that ask for it — insurance renewals, compliance audits, and leadership — with participation, click and compromise rates, training completion, and trend lines. The program is priced in two parts, month to month: $375 per tenant per month, which covers the program itself — tenant setup and upkeep of Attack Simulation Training, campaign design, the new-hire stream, and the monthly and quarterly reporting — plus $3 per enrolled user per month for each person simulated and trained. The scope boundary is explicit: this is the recurring program. A one-time, deeply customized simulation exercise is a separate IT Partner service, and remediating your broader email security posture is separate work we will point you to honestly when the data says you need it.

Success criteria

01The program is fully configured and the baseline simulation campaign completed within the first monthly cycle.
02A simulation campaign runs every month thereafter, with techniques varied across the year rather than repeating one template users learn to spot.
03Users who click or submit credentials receive micro-training assignments automatically, and completion is tracked and chased through agreed reminders.
04New hires are enrolled into the onboarding simulation and training stream without manual per-user requests.
05Quarterly reports are delivered on schedule in a format an insurer, auditor, or board can consume without translation, showing participation, failure rates, training completion, and quarter-over-quarter trend.

What you receive

Program onboarding: licensing verification, Attack Simulation Training configuration in your tenant, simulation scope agreement, and staff communication templates for launch.
A baseline simulation campaign in month one establishing your starting click and compromise rates.
Monthly simulation campaigns designed, launched, and reviewed by IT Partner, rotating payload techniques and difficulty.
Automated micro-training assignments for users who fail simulations, using the training content built into Microsoft Attack Simulation Training, with completion tracking.
A new-hire stream that automatically enrolls new users into a baseline simulation and starter training.
A monthly summary of campaign results to your named contact, and a quarterly evidence report formatted for cyber insurance renewals, compliance audits, and leadership review.
Ongoing program tuning: technique rotation, targeting adjustments, and recommendations when results indicate a deeper email-security problem than training can fix.

How the work unfolds

1. Onboarding and baseline (first monthly cycle)

Verify that enrolled users carry the required Microsoft 365 E5 or Defender for Office 365 Plan 2 licensing, configure Attack Simulation Training in your tenant, agree the simulation scope and communication approach with your leadership, send the launch communication, and run the baseline campaign that sets your starting metrics.

2. Monthly simulation rhythm

Each month IT Partner designs the campaign — technique, lure theme, target groups — launches it, monitors delivery, and reviews results. Techniques rotate deliberately: credential harvest one month, attachment or OAuth-consent patterns another, so the program measures vigilance rather than memory of a single template.

3. Training assignment and follow-through

Users who fail a simulation are automatically assigned short, relevant training modules, with due dates and reminders. Completion is tracked; persistent non-completion is escalated to your named contact rather than silently ignored, because incomplete training is exactly what an auditor will find.

4. New-hire onboarding stream

New users are enrolled automatically into a starter path — baseline simulation plus foundational training — so awareness coverage does not depend on someone remembering to add them.

5. Quarterly reporting and program tuning

Every quarter you receive the evidence report: participation, click and compromise rates, repeat-clicker analysis, training completion, and trend against prior quarters, formatted for insurers and auditors. The quarterly review is also where we tune the program — and where we tell you plainly if the data points to gaps that awareness training cannot close, such as missing email authentication or weak Defender policies.

Prerequisites

Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 licenses for every user enrolled in simulations — this is Microsoft's licensing requirement for Attack Simulation Training, and users without it cannot be included.
Administrative consent to configure Attack Simulation Training and related settings in your tenant, granted to IT Partner under least-privilege access or executed by your administrator with our guidance.
Leadership sign-off on the simulation approach and internal communications, including any works-council, HR, or jurisdictional consultation your organization requires before simulated phishing of employees.
A named client contact who receives monthly summaries, approves campaign scheduling constraints (freeze periods, sensitive teams), and owns internal escalation for training non-completion.

Who does what

IT Partner

  • Configure and operate Attack Simulation Training for the program.
  • Design, schedule, launch, and review the monthly simulation campaigns.
  • Manage training assignment rules, track completion, and escalate persistent non-completion.
  • Operate the new-hire enrollment stream.
  • Deliver monthly summaries and quarterly insurer-and-auditor-ready reports.
  • Recommend program adjustments and flag posture problems the data reveals, with honest routing to the right follow-on service.

Your team

  • Maintain the required licensing for enrolled users and tell us about major workforce changes.
  • Approve the simulation scope, communication plan, and any scheduling constraints.
  • Handle employment-side matters: HR policy alignment, works-council or legal consultation where applicable, and any internal consequences framework for repeat clickers.
  • Reinforce training completion internally when we escalate non-completion.
  • Review quarterly reports and decide on recommended follow-on actions.

What's not included

Microsoft 365 E5 or Defender for Office 365 Plan 2 licenses — licensing is verified during onboarding but never sold as part of this fee.
The one-time, deeply customized simulation exercise with bespoke payload engineering — that is IT Partner's separate Phishing Attack Simulation engagement, which many clients run first as a baseline or annually as a red-team-style complement to this program.
Third-party awareness platforms (KnowBe4, Proofpoint, Hoxhunt, and similar): this program is built deliberately on Microsoft's native platform, and operating another vendor's tool is outside its scope.
Incident response, forensics, or remediation for real phishing attacks or compromised accounts discovered at any point — see the Managed Detection and Response service for continuous monitoring and response.
Defender for Office 365 policy tuning, email authentication (SPF/DKIM/DMARC) remediation, Conditional Access, or broader security hardening — the quarterly review will flag these needs, but fixing them is separately scoped work.
Instructor-led classroom or live security training sessions, custom e-learning production, or translated custom content beyond what the Microsoft training library provides, unless separately scoped.
Guarantees that users will not fall for real phishing, or that any specific insurer, auditor, or framework will accept the program as sufficient — the reports give them the evidence; the judgment is theirs.

Limitations & technical notes

!Attack Simulation Training is a Microsoft feature: available techniques, training modules, and reporting depend on Microsoft's platform and licensing, and Microsoft changes these over time.
!Simulation metrics are indicators, not proof of immunity — click rates vary with campaign difficulty and timing, which is why the program reports trends across varied techniques rather than a single flattering number.
!Users can only be simulated and trained if they hold the required license and an active mailbox; unlicensed populations (shared mailboxes, frontline workers without Plan 2 coverage) fall outside the measurable program and are flagged during onboarding.
!Simulated phishing of employees can have HR and, in some jurisdictions, legal dimensions; the client owns those consultations and decisions, and the program follows the scope leadership approves.
!Insurer and auditor requirements differ; the quarterly report is designed around the evidence commonly requested (cadence, coverage, completion, trend), but each insurer's underwriting decision is its own.

Frequently asked questions

What is the Managed Security Awareness Training and Phishing Simulation service?

It is a recurring, fully managed program that IT Partner operates on Microsoft Attack Simulation Training in Defender for Office 365: monthly phishing simulations with rotating techniques, automatic micro-training for users who fail, an automatic onboarding stream for new hires, and quarterly reports formatted for cyber insurers and auditors. It costs $375 per tenant per month plus $3 per enrolled user per month, with no long-term commitment.

Who is this program for?

Small and mid-size organizations that need continuous, evidenced security awareness training — most commonly because a cyber insurance renewal, a compliance framework, or a customer audit asked for proof of regular phishing simulations and training completion, and a once-a-year test no longer answers the question.

How is this different from IT Partner's one-time Phishing Attack Simulation service?

The one-time engagement is a project: up to three deeply customized payloads built for your environment, executed within a month, with a findings report — excellent as a baseline or an annual red-team-style exercise. This service is the ongoing program: a campaign every month, training follow-through, new-hire coverage, and quarterly evidence reporting, billed monthly per tenant plus per enrolled user. Many clients run the one-time simulation first and roll its results into this program's first quarterly report.

What licensing do we need?

Microsoft requires Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 for users included in Attack Simulation Training — and the license is needed by every simulated user, not just the administrator. Note that Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, which is not sufficient for this feature; Plan 2 is available as an add-on. We verify licensing during onboarding and flag exactly who is covered before anything launches.

What actually happens each month?

IT Partner designs that month's campaign — technique, lure theme, and target groups — launches it through Attack Simulation Training, monitors delivery, and reviews the results. Users who click or submit credentials get training assigned automatically. Your named contact receives a monthly summary; every third month it rolls up into the quarterly evidence report.

What happens when an employee clicks a simulated phish?

Nothing punitive from our side: the user lands on a teachable moment and is automatically assigned a short, relevant training module with a due date and reminders. Results reach your contact in aggregate, with repeat-clicker patterns identified so you can decide how to handle them under your own HR policy — that consequences framework is deliberately yours, not ours.

What is in the quarterly report?

The evidence insurers and auditors actually request: simulation cadence and coverage, click and compromise rates by campaign and technique, training assignment and completion rates, repeat-clicker analysis, new-hire coverage, and quarter-over-quarter trends — presented so it can be attached to a renewal questionnaire or shown to a board without rework.

How are new hires handled?

Automatically. New users are enrolled into an onboarding stream — a baseline simulation plus foundational training — without anyone filing a request. New employees are a favorite phishing target precisely because they do not yet know what internal email looks like, so the program covers them by default rather than by memory.

Why build on Microsoft's platform instead of KnowBe4 or another third-party tool?

Three practical reasons: the capability is already in licensing many organizations own (E5 or Defender for Office 365 Plan 2), it runs natively inside your tenant with no additional vendor processing your employee data, and results integrate with the Microsoft security stack you already operate. If your organization is committed to a third-party platform, this particular service is not the fit — we scope it honestly rather than manage a tool it is not built for.

How does pricing and billing work?

Two components, both monthly. A $375 per tenant per month program fee covers the platform side — configuring and maintaining Attack Simulation Training in your tenant, designing and launching each month's campaign, running the new-hire stream, and producing the monthly summaries and quarterly evidence reports. On top of that, $3 per enrolled user per month covers each person simulated and trained — the users included in the program that month are the users billed. As a worked example, a 100-user organization pays $375 + $300 = $675 per month. Program setup in the first cycle is covered by the tenant fee rather than billed as a separate onboarding charge. It is a month-to-month service with no long-term contract: you can stop at any time, and all we ask is payment of previously approved invoices.

Will simulations disrupt the business or embarrass employees?

The program is designed to build a reporting culture, not a fear culture. Campaigns respect the freeze periods and sensitive-team exclusions you set, individual results are handled through automatic training rather than public callouts, and communications templates for launch are part of onboarding so employees hear about the program from leadership, not from a lure.

Can campaigns be customized to look like our internal systems?

Campaigns are tailored within the program — lure themes, targeting, difficulty, and timing are adjusted to your organization, and techniques rotate monthly. Bespoke payload engineering that deeply mimics your internal applications is the province of the one-time Phishing Attack Simulation engagement, which exists precisely for that depth and pairs well with this program as an annual exercise.

Will this satisfy our cyber insurance requirements?

The program is built around what insurers commonly ask for — regular simulations, measured completion, documented cadence, and trend evidence — and the quarterly report is formatted to answer those questionnaires directly. But no service provider can honestly guarantee an underwriting outcome: insurers differ, and the decision is theirs. What we ensure is that when the question arrives, you have real evidence instead of a scramble.

What if the program reveals a real security problem?

We tell you, in plain terms, in the monthly summary or quarterly review — for example, if failure patterns suggest weak email authentication or missing Defender policies, or if a real incident surfaces during the program. Fixing those problems is separate, honestly scoped work: email security hardening for posture gaps, and the Managed Detection and Response service if you need continuous monitoring and response behind the training layer.

How fast can the program start?

The first monthly cycle covers onboarding end to end: licensing verification, tenant configuration, scope and communications sign-off, and the baseline campaign. From the second cycle the program is in steady state. The main schedule dependency is your side's sign-off on scope and communications — the technical setup is rarely the long pole.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$3 per user per month + $375 per tenant per month
30 days
Start the awareness program