Phishing Attack Simulation with Microsoft Attack Simulation Training — Custom Payloads & User Training
This service implements phishing attack simulations in Microsoft Attack Simulation Training using custom payloads tailored to the client’s environment. It is for organizations using Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 that want employees to practice identifying and responding to phishing attempts, while security teams receive data, reporting, targeted training assignments, and recommendations based on user behavior during the simulation.
What this engagement is
IT Partner configures Microsoft Attack Simulation Training and runs phishing simulations with custom payloads, such as tailored links or attachments, to help employees recognize and respond to phishing threats. The simulation can use social engineering techniques curated from the MITRE ATT&CK® framework, with available payload types including credential harvesting, malware attachments, or links to malicious code. IT Partner works with the client to customize payloads, define target user groups, deploy the simulation, monitor user interactions, assign training based on user actions, and report on results and recommendations. Service details: SKU ITPWW280SECOT; price $1200 per project; duration 10 days; manager Roman Sotnik. Products: Office 365, microsoft 365. Types: Managed Services, Security and Protection.
Success criteria
What you receive
How the work unfolds
Configure Attack Simulation Training environment and confirm licensing requirements.
Collaborate with the client to create and customize phishing payloads to better reflect the organization’s typical threat landscape.
Define user groups and deploy simulations using a range of custom phishing messages and payloads.
Monitor user interactions and gather data on the success or failure of the phishing attempts.
Assign targeted training based on user behavior and responses to the phishing simulations.
Analyze the results of the simulation and create a comprehensive report.
Conduct a post-simulation review meeting to assess findings and offer recommendations.
Prerequisites
Who does what
IT Partner
- Configure the Microsoft Attack Simulation Training environment and confirm licensing.
- Collaborate with the client to create and customize phishing payloads to suit the specific needs and threats relevant to the client’s environment.
- Define the target user groups to receive the simulated phishing messages.
- Deploy phishing campaigns using the defined payloads and social engineering techniques.
- Monitor user interactions with the simulated phishing emails and payloads.
- Collect and analyze data on user actions, such as clicking links, submitting credentials, or opening attachments.
- Assign tailored training based on user actions (e.g., those who fall for phishing attempts will receive additional, focused training).
- Provide users with educational content on identifying and reporting phishing threats.
- Analyze simulation results and provide a detailed report outlining user performance and potential areas for improvement.
- Offer recommendations for enhancing user security awareness and adapting the training based on the client’s environment.
Your team
- Provide access to the Microsoft 365 tenant for deploying Attack Simulation Training.
- Collaborate with IT Partner to define the target user groups for the phishing simulation.
- Review the outcomes of the simulation and collaborate on implementing recommended changes to security practices.
What's not included
Frequently asked questions
What is included in IT Partner’s Phishing Attack Simulation service with Microsoft Attack Simulation Training?
This service includes configuration of Microsoft Attack Simulation Training, creation of custom phishing payloads, definition of target user groups, deployment of simulated phishing campaigns, monitoring of user interactions, targeted training assignments, reporting, recommendations, and a post-simulation review. It is designed for Microsoft 365 environments where employees practice recognizing phishing attempts and security teams receive behavior-based insights.
Who is this phishing simulation service intended for?
This service is intended for organizations using Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 that want to test and improve employee phishing awareness. It is especially relevant for teams that want simulations tailored to their own environment instead of relying only on generic phishing templates.
What Microsoft licensing is required for Attack Simulation Training?
Attack Simulation Training requires Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 licensing. IT Partner confirms licensing as part of the engagement before configuring and deploying the simulation.
How long does the phishing attack simulation engagement take?
The stated duration for this service is 10 days. During that period, IT Partner configures the environment, customizes payloads, deploys the simulation, monitors user actions, assigns training, analyzes results, and conducts a post-simulation review.
How much does the service cost?
The service price is $1200 per project. The stated scope covers the phishing simulation setup and execution using Microsoft Attack Simulation Training with custom payloads, reporting, training assignment, and recommendations based on simulation outcomes.
What types of phishing payloads can be used in the simulation?
The service can use custom payloads such as tailored links, attachments, credential harvesting scenarios, malware attachment simulations, or links to malicious code simulations within Microsoft Attack Simulation Training. The payloads are customized with the client so they reflect the organization’s relevant threat landscape and user context.
Are the phishing simulations based on real-world attack techniques?
Yes, the simulation can use social engineering techniques curated from the MITRE ATT&CK framework. This helps make the phishing scenarios more realistic while still being delivered through Microsoft Attack Simulation Training for awareness and measurement purposes.
What happens during the phishing simulation engagement?
IT Partner first confirms licensing and configures the Attack Simulation Training environment, then collaborates with the client to create custom payloads and define target user groups. IT Partner deploys the phishing campaign, monitors user actions such as clicks or credential submissions, assigns targeted training, analyzes the results, and reviews findings with the client.
What user actions are tracked during the phishing simulation?
The service includes collecting and analyzing user actions such as clicking simulated phishing links, submitting credentials, or opening attachments. These behaviors are used to measure phishing susceptibility and assign targeted training based on how users interacted with the simulation.
Will users receive training after the phishing simulation?
Yes, targeted training is assigned based on user actions during the simulation. For example, users who interact with a simulated phishing payload can receive focused educational content on identifying and reporting phishing threats.
What reporting is provided after the simulation?
IT Partner provides a detailed report outlining user performance, observed behavior, potential areas for improvement, and recommendations for strengthening security awareness. The engagement also includes a post-simulation review meeting to assess the findings and discuss next steps.
What responsibilities does IT Partner handle in this service?
IT Partner configures Microsoft Attack Simulation Training, confirms licensing, creates and customizes phishing payloads, defines target user groups with the client, deploys the simulation, monitors interactions, analyzes results, assigns tailored training, and provides reporting and recommendations. IT Partner also provides educational content to help users recognize and report phishing threats.
What responsibilities does the client have during the engagement?
The client provides access to the Microsoft 365 tenant, collaborates with IT Partner to define target user groups, and reviews the simulation outcomes. The client is also responsible for working with IT Partner on implementing recommended changes to security practices after the engagement.
Does the service require access to our Microsoft 365 tenant?
Yes, the client must provide access to the Microsoft 365 tenant so IT Partner can configure and deploy Microsoft Attack Simulation Training. The exact access method and permissions should be confirmed with IT Partner during project kickoff.
Can the simulation target specific departments or user groups?
Yes, defining target user groups is part of the service. IT Partner collaborates with the client to determine which users or groups should receive the simulated phishing messages.
Will the phishing simulation cause downtime or disrupt Microsoft 365 services?
The service description does not state that Microsoft 365 downtime is required, because the engagement is focused on configuring and running Attack Simulation Training campaigns. Users may experience simulated phishing emails and assigned training activities, so any business impact should be planned and confirmed with IT Partner before launch.
What happens after the phishing simulation is completed?
After the simulation, IT Partner analyzes the results, provides a detailed report, assigns or recommends training based on user behavior, and conducts a post-simulation review meeting. The client reviews the outcomes and collaborates on applying recommended improvements to security awareness practices.
What is not included in this phishing simulation service?
The AI-drafted exclusions should be reviewed and confirmed before publication. They identify items outside the fixed simulation scope, such as license purchase or renewal, broader Microsoft 365 security remediation, additional simulation waves, real-incident response, HR or legal approvals, disciplinary follow-up, third-party platform work, large-scale creative production, broad end-user help desk support, and any guarantee that phishing risk will be eliminated.
Does this service guarantee that employees will stop falling for phishing attacks?
No guarantee is stated in the service scope. The service strengthens security awareness by giving employees practical phishing recognition experience, assigning targeted training, and providing reporting and recommendations, but phishing risk reduction depends on user behavior and follow-through on recommended actions.