Phishing Attack Simulation with Microsoft Attack Simulation Training — Custom Payloads & User Training
This service implements phishing attack simulations in Microsoft Attack Simulation Training using custom payloads tailored to the client’s environment. It is for organizations using Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 that want employees to practice identifying and responding to phishing attempts, while security teams receive data, reporting, targeted training assignments, and recommendations based on user behavior during the simulation.
What this engagement is
IT Partner configures Microsoft Attack Simulation Training and runs phishing simulations with custom payloads, such as tailored links or attachments, to help employees recognize and respond to phishing threats. The simulation can use social engineering techniques curated from the MITRE ATT&CK® framework, with available payload types including credential harvesting, malware attachments, or links to malicious code. IT Partner works with the client to customize payloads, define target user groups, deploy the simulation, monitor user interactions, assign training based on user actions, and report on results and recommendations. Attack simulation training runs in the Microsoft Defender portal and requires Microsoft Defender for Office 365 Plan 2 — included in Microsoft 365 E5 or available as an add-on. The engagement includes up to 3 custom payloads, and the full engagement — setup, simulation, monitoring, training assignment, and reporting — completes within one calendar month.
Success criteria
What you receive
How the work unfolds
Configure Attack Simulation Training environment and confirm licensing requirements.
Collaborate with the client to create and customize up to 3 phishing payloads to better reflect the organization’s typical threat landscape.
Define user groups and deploy simulations using a range of custom phishing messages and payloads.
Monitor user interactions and gather data on the success or failure of the phishing attempts.
Assign targeted training based on user behavior and responses to the phishing simulations.
Analyze the results of the simulation and create a comprehensive report.
Conduct a post-simulation review meeting to assess findings and offer recommendations.
Prerequisites
Who does what
IT Partner
- Configure the Microsoft Attack Simulation Training environment and confirm licensing.
- Collaborate with the client to create and customize up to 3 phishing payloads to suit the specific needs and threats relevant to the client’s environment.
- Define the target user groups to receive the simulated phishing messages.
- Deploy phishing campaigns using the defined payloads and social engineering techniques.
- Monitor user interactions with the simulated phishing emails and payloads.
- Collect and analyze data on user actions, such as clicking links, submitting credentials, or opening attachments.
- Assign tailored training based on user actions (e.g., those who fall for phishing attempts will receive additional, focused training).
- Provide users with educational content on identifying and reporting phishing threats.
- Analyze simulation results and provide a detailed report outlining user performance and potential areas for improvement.
- Offer recommendations for enhancing user security awareness and adapting the training based on the client’s environment.
Your team
- Provide access to the Microsoft 365 tenant for deploying Attack Simulation Training.
- Collaborate with IT Partner to define the target user groups for the phishing simulation.
- Review the outcomes of the simulation and collaborate on implementing recommended changes to security practices.
What's not included
Limitations & technical notes
Frequently asked questions
What is included in IT Partner’s Phishing Attack Simulation service with Microsoft Attack Simulation Training?
This service includes configuration of Microsoft Attack Simulation Training, creation of up to 3 custom phishing payloads, definition of target user groups, deployment of simulated phishing campaigns, monitoring of user interactions, targeted training assignments, reporting, recommendations, and a post-simulation review. It is designed for Microsoft 365 environments where employees practice recognizing phishing attempts and security teams receive behavior-based insights.
Who is this phishing simulation service intended for?
This service is intended for organizations using Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 that want to test and improve employee phishing awareness. It is especially relevant for teams that want simulations tailored to their own environment instead of relying only on generic phishing templates.
What Microsoft licensing is required for Attack Simulation Training?
Attack simulation training requires Microsoft Defender for Office 365 Plan 2, which is included in Microsoft 365 E5 or available as a standalone add-on. IT Partner confirms licensing as part of the engagement before configuring and deploying the simulation.
How long does the phishing attack simulation engagement take?
The stated duration for this service is 10 days, and the full engagement — setup, simulation, monitoring, training assignment, and reporting — completes within one calendar month. During that period, IT Partner configures the environment, customizes up to 3 payloads, deploys the simulation, monitors user actions, assigns training, analyzes results, and conducts a post-simulation review.
How much does the service cost?
The service is $2,900 per project. The scope covers the phishing simulation setup and execution using Attack simulation training with custom payloads, reporting, training assignment, and recommendations based on simulation outcomes.
What types of phishing payloads can be used in the simulation?
The service can use custom payloads such as tailored links, attachments, credential harvesting scenarios, malware attachment simulations, or links to malicious code simulations within Microsoft Attack Simulation Training. The payloads — up to 3 per engagement — are customized with the client so they reflect the organization’s relevant threat landscape and user context.
Are the phishing simulations based on real-world attack techniques?
Yes, the simulation can use social engineering techniques curated from the MITRE ATT&CK framework. This helps make the phishing scenarios more realistic while still being delivered through Microsoft Attack Simulation Training for awareness and measurement purposes.
What user actions are tracked during the phishing simulation?
The service includes collecting and analyzing user actions such as clicking simulated phishing links, submitting credentials, or opening attachments. These behaviors are used to measure phishing susceptibility and assign targeted training based on how users interacted with the simulation.
Will users receive training after the phishing simulation?
Yes, targeted training is assigned based on user actions during the simulation. For example, users who interact with a simulated phishing payload can receive focused educational content on identifying and reporting phishing threats.
Can the simulation target specific departments or user groups?
Yes, defining target user groups is part of the service. IT Partner collaborates with the client to determine which users or groups should receive the simulated phishing messages.
Will the phishing simulation cause downtime or disrupt Microsoft 365 services?
No. The engagement configures and runs Attack simulation training campaigns — no downtime is involved. Users in the target groups receive simulated phishing emails and, depending on their actions, follow-up training assignments; normal mail flow and services are unaffected.
What is not included in this phishing simulation service?
License purchase or renewal, broader Microsoft 365 security remediation (Defender policy tuning, Conditional Access, identity hardening, mail flow or endpoint changes), additional simulation waves or recurring campaigns beyond the agreed engagement of up to 3 payloads within one calendar month, and incident response for real phishing attacks are not included — each can be quoted as a separate engagement.