Companies on E5 or Defender for Office 365 Plan 2 are usually paying twice for phishing simulation.
The feature sends convincing phishing to your own people using seven techniques drawn from MITRE, estimates how many of them a given message will catch before it leaves the building, and pushes training only at the people who need it. What we find repeatedly is an American company paying a separate vendor a five-figure annual sum for this, while the identical capability sits switched off in a tenant they already license.

- IncludedIncluded with Microsoft 365 E5 or Defender for Office 365 Plan 2
- Seven techniquesSix from MITRE ATT&CK, plus guides
- QR codesPayloads and training modules for both
- CalibratedPredicted compromise rate before you send
Check what you already own before buying a simulation vendor.
This is worth stating precisely, because it is the question that decides whether this page describes a purchase or a configuration exercise.
- Microsoft states that attack simulation training requires a Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 license. If you hold either, the full capability on this page is already included in what you pay for.
- There is a subset available to Microsoft 365 E3 customers as a trial. Microsoft describes it as containing a Credential Harvest payload and the ability to select the ISA Phishing or Mass Market Phishing training experiences, with no other capabilities included, so it is a taste rather than a program.
- There is also a 90-day Defender for Office 365 Plan 2 trial covering the full feature set, which is a legitimate way to run a first campaign and evaluate the product against whatever you currently pay a third party for.
- Availability is regional: Microsoft lists attack simulation training as available in the APC, EUR and NAM regions. The documented gap around reported email telemetry applies to the latest-added countries on that list, not to North American tenants. We confirm the current position against your specific tenant before scoping anything.
Eight things it does, beginning with the one that determines whether the rest is worth running.
Predicted compromise rate, before you send anything
The prediction draws on historical data across Microsoft 365 to estimate what share of recipients a given message will catch, weighing the content itself, its metadata, and anonymized aggregate results from simulations elsewhere. Afterwards you hold that estimate against what actually happened. That single comparison is the difference between a stunt and a measurement with a baseline you can improve against.
Seven techniques, six of them from MITRE ATT&CK
Six techniques come from the MITRE ATT&CK framework: credential harvest, malware attachment, link in attachment, link to malware, drive-by URL, and consent grant. A seventh, the how-to guide, teaches instead of testing. Consent grant is the one almost nobody has ever simulated, and it happens to be the pattern growing fastest against American tenants.
QR code payloads, for a reflex people no longer question
Across several techniques the link can arrive as a scannable code instead of a written address, and there are ready-made payloads for it plus two training modules, one for codes on a screen and one for codes printed on paper. Between restaurant menus, parking meters, and conference badges, Americans scan these dozens of times a month without pausing. Very few tools test that reflex at all.
Payload harvesting from your own real phishing
Payload harvesting takes real phishing that your own tenant caught, strips it of anything dangerous, and turns it into the simulation. That beats a generic template by a wide margin, because it reflects what is genuinely being aimed at your company and your industry rather than what a template author imagined might be plausible.
Training assigned by behavior, not by calendar
What someone receives afterwards depends on what they actually did, and the product accounts for the right actions as well as the wrong ones. The person who reported the message needs something very different from the person who typed their password into it. That precision is what makes the training worth an employee half hour, and it is the exact opposite of the annual module everyone clicks through with the video muted.
Training campaigns and guides, with no test at all
Training can be assigned on its own without anybody being tested, which fits a monthly awareness rhythm well. The how-to guides are short pieces people read in their inbox, with ready-made ones on reporting phishing and on spotting a malicious scannable code. Not every intervention has to be a trap, and opening with a guide buys goodwill you will need later.
Department by department comparison
Run the same simulation separately against each department and compare the results side by side. That converts one company-wide percentage into something you can act on, because finance clicking at three times the rate of engineering is a specific problem with a specific fix, and the combined figure conceals it entirely.
Roles that do not require Global Administrator
There are purpose-built roles for this. One creates and runs campaigns, another writes payloads for somebody else to launch, and read-only roles exist for anyone who just needs to see results. Microsoft is explicit about least privilege and about keeping Global Administrator for emergencies, which means whoever runs your phishing program has no business holding the keys to the tenant.
Four things that separate a program from an embarrassment.
We calibrate with predicted compromise rate before sending
Microsoft says outright that a payload can be pitched too easy or too hard, and the prediction feature exists for precisely that reason. We choose messages whose predicted rate will generate a usable signal, then set predicted against actual afterwards. That comparison is what turns the exercise into a measurement instead of a story about one unusually clever email.
We agree the culture position before the first campaign
Do individual results go to line managers, are executives in scope, and how is any of it communicated. Get these wrong and the lesson people retain is that IT lays traps, which quietly kills genuine reporting and leaves you worse off than before the program existed. Get them right and reporting climbs, which is the number that actually protects you.
We use your real phishing, not stock templates
Harvesting turns mail that genuinely landed in your tenant into a safe simulation. The result reflects what is actually being aimed at your company and your industry, which makes the number more honest and the follow-up conversation far easier when someone asks why they fell for it.
We measure by department and act on the difference
Running the same campaign per department and comparing is where the useful number lives. A company-wide click rate is a headline for a slide. Knowing one team clicks four times as often as another is a plan, and it usually turns out to be a workload or process problem rather than an awareness one.
Six US situations where a simulation program earns its place.
A firm expected to evidence awareness testing
SOC 2 assessors, cyber carriers at renewal, and rules like the FTC Safeguards Rule and NYDFS Part 500 all carry personnel training expectations, and the question they now ask is how awareness gets tested rather than whether a course was delivered. Click rates, reporting rates, and a trend line answer that with evidence. A completion certificate answers it with paperwork.
Any organization where finance approves payments
Business email compromise goes after the handful of people who can authorize a payment, and generic training never reaches them with the specificity they need. Scoping a campaign to exactly that group, using a message built around the invoice and payment-redirect patterns actually run against American firms, tests the control with the most money behind it.
Retail, hospitality and anywhere QR codes are normal
Staff and customers scan codes without thinking, on menus, parking meters, shipping labels, and event passes, and that reflex is exactly what an attacker rents. The scannable-code payloads and the two modules covering codes on screens and codes on paper address a behavior conventional phishing training ignores completely.
An organization that has already had an incident
Once something has actually happened, the board asks one question: could it happen again. A simulation program answers with a number that gets better each quarter. Harvesting fits this moment perfectly, because the message that succeeded can become the test everyone else now has to pass.
A large workforce with limited computer experience
Construction, trucking, manufacturing, and facilities companies employ a lot of people who did not grow up in an inbox. Leading with the teaching guides, which instruct without testing anyone, and only then moving to simulations, works far better than opening with a trap most of the workforce will walk into.
Paying for Plan 2 and never once opening this part of it
This is what we run into most. The capability comes with Microsoft 365 E5 and with Defender for Office 365 Plan 2, and companies holding either are often also paying a specialist vendor for the same thing. Working out what you already own takes about five minutes and occasionally saves a renewal.
How organizations actually test whether staff would fall for phishing.
| Feature | Simulation program | Annual training module | Nothing |
|---|---|---|---|
You know your actual click rate | Yes | No | No |
You know which departments are weakest | Yes | No | No |
Training targets people who need it | Yes | No | No |
QR code behavior tested | Yes | No | No |
OAuth consent behavior tested | Yes | No | No |
Payloads reflect your real threats | Yes | No | No |
Difficulty calibrated before sending | Yes | Not applicable | Not applicable |
Improvement measurable over time | Yes | No | No |
Evidence for an auditor or cyber insurer | Strong | Weak | None |
Satisfies a security questionnaire honestly | Yes | Barely | No |
What each of the seven actually tests, and which population it suits.
Technique
Credential harvest
- What it simulates
- A link opening a page dressed as somewhere familiar, which then asks for a username and password
Technique
Malware attachment
- What it simulates
- An attached file that executes something, typically a macro, the moment it is opened
Technique
Link in attachment
- What it simulates
- The two combined, with the credential-stealing link buried inside an attachment instead of the message body
Technique
Link to malware
- What it simulates
- A link pointing at a file hosted somewhere trusted, SharePoint or Dropbox being the usual choices
Technique
Drive-by URL
- What it simulates
- A familiar site, either cloned or genuinely compromised, quietly running code in the background. The watering hole pattern
Technique
OAuth consent grant
- What it simulates
- An application asking the user to approve access to their data, most often the mailbox itself
Technique
How-to guide
- What it simulates
- Instruction rather than examination, such as showing people how to report something suspicious
Technique
QR code variants
- What it simulates
- Several of the techniques above can present the link as a scannable code rather than a visible address
Five phases, and the opening campaign matters least of all of them.
- 1
Confirm entitlement
We establish whether you hold E5 or Plan 2, whether the ninety day Plan 2 trial is the sensible route instead, and what you are currently paying a third party for that this would replace. We check rather than assume, because Microsoft moves these boundaries.
- 2
Agree the culture position with leadership
Do individual results reach line managers, are executives included, how do you communicate outcomes, and what happens to a person who clicks. That conversation takes an hour, and it decides whether reporting rates rise or collapse.
- 3
Design the first campaign and calibrate it
We choose the technique, the message, and who receives it, using the predicted rate to land on something that yields a useful signal rather than a flattering result or a brutal one. Permissions are set correctly at the same time, through the dedicated simulation administrator role rather than somebody tenant admin account.
- 4
Run, assign training and read the departmental split
Training goes to people based on what they did rather than to everyone regardless, and departments are compared using identical campaigns so the differences are real. That breakdown is nearly always where the useful finding sits, and it more often indicts a process than a person.
- 5
Establish the rhythm and start harvesting
Scheduling moves to automation, harvesting starts feeding real phishing from your own tenant into future campaigns, and the technique mix widens over time to include consent grant and scannable codes. From there, watch the reporting rate rather than only the click rate, because reporting is the behavior you are actually trying to build.
What organizations ask about attack simulation training.
Fifteen questions worth answering first.
Entitlement
- Are you licensed for Defender for Office 365 Plan 2, or Microsoft 365 E5?Those are the stated license requirements.
- On E3, do you know exactly what the trial gives you?A credential harvest payload and two training experiences only.
- Have you considered the 90 day Plan 2 trial?It exists and covers the full capability.
- Are you paying a separate simulation vendor?Compare it against what you already hold.
- Do you have on-premises mailboxes?Supported, with reduced reporting functionality.
Program design
- Before you send it, what does the tool predict that message will catch?Calibrate before sending, not after.
- Will you scope simulations by department?Microsoft suggests identical simulations per department to compare.
- Have you tried anything beyond credential harvest?OAuth consent grant is the underused one.
- Are QR code payloads in scope?They test a reflex traditional training never touches.
- Will you harvest payloads from your own real phishing?A better test than any generic template.
Culture
- Has leadership agreed this is measurement, not a trap?The framing decides the outcome.
- Will individual results be shared with managers?Decide before the first campaign, and be consistent.
- Are executives included in the population?Excluding them undermines the exercise.
- Can an employee report a suspect message without effort or hesitation?Reporting is the behavior you are trying to build.
- Who runs the program, and with which role?Attack Simulation Administrator, not Global Administrator.
The pages around this one.
Security awareness training
The vendor-neutral program this fits inside, covering policy, live sessions and staff who do not work at a desk.
Defender for Office 365
The wider product this sits inside, with the plan comparison and a quick way to work out which one you hold.
Anti-phishing policies
The technical half of the same problem: the configuration your simulations should be testing alongside.
Find out whether you are about to buy something twice.
Hold Microsoft 365 E5 or Defender for Office 365 Plan 2 and this is already yours. A striking number of American companies pay a separate vendor for it anyway. Confirming which side of that line you are on takes five minutes, and we do it in the first conversation at no cost.
Related Services
Explore more solutions that work great with this service
Security Awareness Training Programs
Security awareness training programs for US businesses: role-based
Learn moreMicrosoft 365 Anti-Phishing Policy Configuration
Anti-phishing policy reviews for US organizations: policy inventory
Learn moreMicrosoft Defender for Office 365 Services
Anti-phishing, Safe Links and Safe Attachments done right
Learn morePhishing Protection for US Businesses
Layered phishing protection for US businesses combining technical
Learn moreEmail Security Audit
Email security audits for US organizations: sending domain inventory
Learn moreMicrosoft Security Services
The Microsoft security stack deployed and managed end to end
Learn more