First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Phishing Attack Simulation with Microsoft Attack Simulation Training using custom payload
Managed ServicesSecurity and Protection

Phishing Attack Simulation with Microsoft Attack Simulation Training — Custom Payloads & User Training

This service implements phishing attack simulations in Microsoft Attack Simulation Training using custom payloads tailored to the client’s environment. It is for organizations using Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 that want employees to practice identifying and responding to phishing attempts, while security teams receive data, reporting, targeted training assignments, and recommendations based on user behavior during the simulation.

Timeline 10 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

IT Partner configures Microsoft Attack Simulation Training and runs phishing simulations with custom payloads, such as tailored links or attachments, to help employees recognize and respond to phishing threats. The simulation can use social engineering techniques curated from the MITRE ATT&CK® framework, with available payload types including credential harvesting, malware attachments, or links to malicious code. IT Partner works with the client to customize payloads, define target user groups, deploy the simulation, monitor user interactions, assign training based on user actions, and report on results and recommendations. Attack simulation training runs in the Microsoft Defender portal and requires Microsoft Defender for Office 365 Plan 2 — included in Microsoft 365 E5 or available as an add-on. The engagement includes up to 3 custom payloads, and the full engagement — setup, simulation, monitoring, training assignment, and reporting — completes within one calendar month.

Success criteria

01Employees gain practical experience in recognizing and responding to phishing attacks.
02Custom payloads are tailored to reflect the client’s environment, increasing the relevance and effectiveness of the training.
03Detailed insights into organizational vulnerability to phishing attacks.
04Targeted training for users based on their interaction with the phishing simulations.
05Strengthened cybersecurity posture through the identification and remediation of user weaknesses.
06Comprehensive reporting on user behavior and recommendations for enhanced security awareness.

What you receive

Configured Microsoft Attack Simulation Training environment with licensing confirmed.
Up to 3 custom phishing payloads created and customized to suit the specific needs and threats relevant to the client’s environment.
Defined target user groups for the simulated phishing messages.
Deployed phishing campaigns using the defined payloads and social engineering techniques.
Monitoring of user interactions with simulated phishing emails and payloads.
Collected and analyzed data on user actions, such as clicking links, submitting credentials, or opening attachments.
Tailored training assigned based on user actions.
Educational content provided to users on identifying and reporting phishing threats.
Detailed report outlining user performance and potential areas for improvement.
Recommendations for enhancing user security awareness and adapting the training based on the client’s environment.
Post-simulation review meeting to assess findings and offer recommendations.

How the work unfolds

Configure environment and confirm licensing

Configure Attack Simulation Training environment and confirm licensing requirements.

Create and customize phishing payloads

Collaborate with the client to create and customize up to 3 phishing payloads to better reflect the organization’s typical threat landscape.

Define user groups and deploy simulations

Define user groups and deploy simulations using a range of custom phishing messages and payloads.

Monitor interactions and gather data

Monitor user interactions and gather data on the success or failure of the phishing attempts.

Assign targeted training

Assign targeted training based on user behavior and responses to the phishing simulations.

Analyze results and create report

Analyze the results of the simulation and create a comprehensive report.

Conduct post-simulation review

Conduct a post-simulation review meeting to assess findings and offer recommendations.

Prerequisites

Attack simulation training requires Microsoft Defender for Office 365 Plan 2 — included in Microsoft 365 E5 or available as an add-on.

Who does what

IT Partner

  • Configure the Microsoft Attack Simulation Training environment and confirm licensing.
  • Collaborate with the client to create and customize up to 3 phishing payloads to suit the specific needs and threats relevant to the client’s environment.
  • Define the target user groups to receive the simulated phishing messages.
  • Deploy phishing campaigns using the defined payloads and social engineering techniques.
  • Monitor user interactions with the simulated phishing emails and payloads.
  • Collect and analyze data on user actions, such as clicking links, submitting credentials, or opening attachments.
  • Assign tailored training based on user actions (e.g., those who fall for phishing attempts will receive additional, focused training).
  • Provide users with educational content on identifying and reporting phishing threats.
  • Analyze simulation results and provide a detailed report outlining user performance and potential areas for improvement.
  • Offer recommendations for enhancing user security awareness and adapting the training based on the client’s environment.

Your team

  • Provide access to the Microsoft 365 tenant for deploying Attack Simulation Training.
  • Collaborate with IT Partner to define the target user groups for the phishing simulation.
  • Review the outcomes of the simulation and collaborate on implementing recommended changes to security practices.

What's not included

Purchase, assignment, or renewal of Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 licenses is not included unless separately contracted.
Remediation or implementation of broader Microsoft 365 security controls, such as Defender for Office 365 policy tuning, Conditional Access, identity hardening, mail flow changes, or endpoint security configuration, is outside this fixed simulation scope.
Additional simulation waves, recurring phishing campaigns, retesting, or a long-term security awareness program beyond the agreed engagement — up to 3 custom payloads, completing within one calendar month — are not included unless separately scoped.
Incident response, forensic investigation, or compromise remediation for real phishing attacks or security incidents discovered during the engagement is not included.
Legal, HR, works council, union, privacy, or internal policy approvals for conducting phishing simulations remain the client’s responsibility.
Disciplinary actions, performance management, or employee-specific HR follow-up based on simulation results are not included.
Custom application development, third-party phishing platform implementation, non-Microsoft integrations, or custom reporting outside Microsoft Attack Simulation Training exports and agreed reporting are not included.
Large-scale custom creative production, advanced branding packages, or multilingual content beyond the agreed custom payload scope may require additional effort and separate approval.
End-user help desk support for all user questions after campaign launch is not included, except for agreed educational content and project-related guidance.
Guaranteed reduction in phishing click rates or elimination of phishing risk is not included; outcomes depend on user behavior, organizational follow-through, and ongoing training.

Limitations & technical notes

!The scope includes up to 3 custom payloads; the engagement, including reporting and the post-simulation review, completes within one calendar month.

Frequently asked questions

What is included in IT Partner’s Phishing Attack Simulation service with Microsoft Attack Simulation Training?

This service includes configuration of Microsoft Attack Simulation Training, creation of up to 3 custom phishing payloads, definition of target user groups, deployment of simulated phishing campaigns, monitoring of user interactions, targeted training assignments, reporting, recommendations, and a post-simulation review. It is designed for Microsoft 365 environments where employees practice recognizing phishing attempts and security teams receive behavior-based insights.

Who is this phishing simulation service intended for?

This service is intended for organizations using Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 that want to test and improve employee phishing awareness. It is especially relevant for teams that want simulations tailored to their own environment instead of relying only on generic phishing templates.

What Microsoft licensing is required for Attack Simulation Training?

Attack simulation training requires Microsoft Defender for Office 365 Plan 2, which is included in Microsoft 365 E5 or available as a standalone add-on. IT Partner confirms licensing as part of the engagement before configuring and deploying the simulation.

How long does the phishing attack simulation engagement take?

The stated duration for this service is 10 days, and the full engagement — setup, simulation, monitoring, training assignment, and reporting — completes within one calendar month. During that period, IT Partner configures the environment, customizes up to 3 payloads, deploys the simulation, monitors user actions, assigns training, analyzes results, and conducts a post-simulation review.

How much does the service cost?

The service is $2,900 per project. The scope covers the phishing simulation setup and execution using Attack simulation training with custom payloads, reporting, training assignment, and recommendations based on simulation outcomes.

What types of phishing payloads can be used in the simulation?

The service can use custom payloads such as tailored links, attachments, credential harvesting scenarios, malware attachment simulations, or links to malicious code simulations within Microsoft Attack Simulation Training. The payloads — up to 3 per engagement — are customized with the client so they reflect the organization’s relevant threat landscape and user context.

Are the phishing simulations based on real-world attack techniques?

Yes, the simulation can use social engineering techniques curated from the MITRE ATT&CK framework. This helps make the phishing scenarios more realistic while still being delivered through Microsoft Attack Simulation Training for awareness and measurement purposes.

What user actions are tracked during the phishing simulation?

The service includes collecting and analyzing user actions such as clicking simulated phishing links, submitting credentials, or opening attachments. These behaviors are used to measure phishing susceptibility and assign targeted training based on how users interacted with the simulation.

Will users receive training after the phishing simulation?

Yes, targeted training is assigned based on user actions during the simulation. For example, users who interact with a simulated phishing payload can receive focused educational content on identifying and reporting phishing threats.

Can the simulation target specific departments or user groups?

Yes, defining target user groups is part of the service. IT Partner collaborates with the client to determine which users or groups should receive the simulated phishing messages.

Will the phishing simulation cause downtime or disrupt Microsoft 365 services?

No. The engagement configures and runs Attack simulation training campaigns — no downtime is involved. Users in the target groups receive simulated phishing emails and, depending on their actions, follow-up training assignments; normal mail flow and services are unaffected.

What is not included in this phishing simulation service?

License purchase or renewal, broader Microsoft 365 security remediation (Defender policy tuning, Conditional Access, identity hardening, mail flow or endpoint changes), additional simulation waves or recurring campaigns beyond the agreed engagement of up to 3 payloads within one calendar month, and incident response for real phishing attacks are not included — each can be quoted as a separate engagement.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$2,900 per project
10 days
Book a meeting