Skip to content
Browse all topics
Microsoft Defender (Security)

Attack Simulation Training in Defender for Office 365

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

How to run controlled phishing simulations and embedded training to harden users against real attacks.

3 min read

Share as imagePNG

Attack Simulation Training is a feature of Microsoft Defender for Office 365 Plan 2 that lets you run controlled phishing simulations against your own users, measure click-through rates, and automatically enrol users who fall for them in training. It's how you stop guessing how susceptible your users are and start measuring.

What you can simulate

The simulation engine ships with a library of techniques real attackers use:

  • Credential harvest — a fake sign-in page that captures clicks.
  • Malware attachment — an attachment that triggers a click metric (no real payload).
  • Link in attachment — a clickable link inside a document.
  • Link to malware — a clickable link to a "malicious" URL.
  • Drive-by URL — a link that simulates a watering-hole compromise.
  • OAuth consent grant — a fake app requesting Microsoft 365 permissions.

Each technique comes with built-in payloads, and you can add your own with custom branding and copy. The payload picker lets you choose by industry, sophistication, and current threat trends.

Targeting and scheduling

  • Targeting: a specific group of users, a department, the whole tenant. Repeat offender targeting picks users who clicked previous simulations.
  • Delivery: one-shot or automated campaigns running on schedules.
  • Region awareness: deliveries can be staggered across time zones.
  • Sender impersonation: simulate internal senders, partner brands, or random external senders.

Training

When a user clicks, they're redirected to training content:

  • Built-in microlearning modules covering the specific technique.
  • Nudge training for first-time clickers, full training for repeat clickers.
  • Optional training-only assignments to specific groups without a simulation.

Training completion is tracked, and you can require it before lifting the consequences of a click (typically a Teams notification or manager email).

Reporting

The simulation surface includes:

  • Per-campaign reports — click rates, training completion, recidivism.
  • Per-user dashboards for managers — who's clicked what.
  • Trend reports over time.
  • Susceptibility comparisons against industry baselines.

Repeat-offender lists are the most useful output: a small number of users tend to drive the bulk of risk, and targeted coaching for those individuals beats blanket training every time.

Operational discipline

A simulation programme is most effective when it's regular and visible:

  • Monthly cadence, escalating sophistication over time.
  • Clear communication to users that simulations happen (don't try to "trick" without ever telling them — that breaks trust).
  • No HR consequences for clicking — culture beats compliance.
  • Tie outcomes to Defender XDR so high-risk users get tighter Conditional Access.

For tenants on E5 or Defender for Office 365 Plan 2, attack simulation is essentially free and pays back disproportionately compared to other training.

Simulation exclusions and the trust cost of getting them wrong

Every simulation platform needs the simulated phishing messages to bypass the tenant's own anti-phishing filters — otherwise Defender would simply quarantine its own test messages before they ever reach a user's inbox. This requires a scoped mail-flow exclusion (an advanced delivery policy) for the simulation platform's specific sending infrastructure, applied narrowly enough that it doesn't become a general phishing bypass for anyone who discovers the excluded sender pattern. A poorly scoped exclusion — matching too broad a sender range, or never reviewed after being set up — is itself a security gap; the exclusion should be reviewed alongside other mail-flow rules during any security audit, not treated as a one-time setup step that never needs revisiting.

Frequently asked questions

Can users tell a simulation apart from a real phishing attempt after they've seen a few? That's actually the point, not a flaw — as users learn to recognise a tenant's own simulation patterns, the payload picker and custom payload options let admins vary sophistication and source style, and the real goal is building general suspicion of urgency, unexpected links, and credential requests, not memorising the specific look of one simulation template.

Should simulation results factor into performance reviews? Most security-culture guidance says no — tying click rates to individual performance evaluation tends to drive under-reporting and resentment rather than genuine behaviour change; the more effective pattern uses aggregate trends to guide organisation-wide training investment while keeping individual results private and coaching-oriented rather than punitive.

Was this useful?

Spot something wrong or want a topic covered? Send it through the contact form.