13.1 Managing Attack Simulations & Training
Key Takeaways
- Attack simulation training requires Microsoft Defender for Office 365 Plan 2 or Microsoft 365 E5; it is not available with Plan 1 or Exchange Online Protection alone
- Payload categories include credential harvest, malware attachment, link in attachment, link to malware, drive-by URL, OAuth consent grant, and text-only smishing attempts
- Simulation automations run payloads on a recurring schedule without admin intervention, while one-time simulations are manual launches against a selected audience
- Training modules are assigned automatically based on user behavior — users who click or enter credentials receive targeted modules while those who do not click can still receive awareness training
- The key operational metrics are click rate, compromise rate, training completion rate, and repeat-offender tracking across campaigns
What Attack Simulation Training Is
Attack simulation training is a capability in Microsoft Defender for Office 365 Plan 2 (included with Microsoft 365 E5, or available as an add-on to Plan 1) that lets administrators run realistic, safe phishing and social-engineering simulations against their own users and assign training based on the results. It is educational by design — no real payload is delivered, no credentials are captured, and no malware executes. The goal is to measure user susceptibility and drive behavior change through repeated, context-aware training.
Licensing note: Attack simulation training is not available with Exchange Online Protection (EOP) alone or Defender for Office 365 Plan 1. Verify Plan 2 (or E5) is assigned to every user you target; users without the license are skipped.
Where It Lives in the Portal
In the Microsoft Defender portal (https://security.microsoft.com), attack simulation training lives under Email & collaboration → Attack simulation training. From there you reach three core areas: Simulations (launch and track individual campaigns), Simulation automations (schedule recurring payload sequences), and the Payloads library (browse and choose social-engineering templates). An Automations tab also exposes payload automations you can enable with one click.
Payload Categories
When you create a simulation, you choose a payload — the template that defines the lure and the technique. Microsoft maintains a curated library and your tenant can also create custom payloads. The supported technique categories are:
| Technique | What the user sees | What is measured |
|---|---|---|
| Credential harvest | A fake sign-in page asking for username/password | Credentials entered on the fake login page |
| Malware attachment | An email with a malicious-looking attachment | Attachment opened or downloaded |
| Link in attachment | An attachment containing a link to a phishing site | Link clicked from the attachment |
| Link to malware | A link in the email body pointing to a malware download | Link clicked |
| Drive-by URL | A link to a compromised-looking site that silently “infects” | Link clicked |
| OAuth consent grant | A prompt asking the user to grant app permissions | Consent granted |
| Text-only (smishing) | A short SMS-style message with a link | Link clicked |
Each payload includes a landing page (what the user sees after clicking) and, for credential-harvest payloads, a login page (the fake sign-in form). You can use Microsoft's default landing pages, clone and customize them, or build your own. Landing pages should include a “this was a simulation” banner and a link to the assigned training.
Targeting and Scheduling
A simulation targets an audience — one or more mail-enabled groups, or a manually selected set of users. Best practice is to start with a small pilot group and expand. You can exclude service accounts and shared mailboxes.
Scheduling has two modes:
- One-time (manual): You configure everything and launch now or at a fixed date/time. Use this for controlled, point-in-time tests.
- Automated (recurring): You configure a simulation automation that selects payloads from a category and runs them on a schedule — for example, “run one random credential-harvest payload every Tuesday at 9 AM against all staff for 6 months.” Automations eliminate admin overhead and produce trend data over time.
Training Assignment
This is the part that turns a test into a program. When you configure a simulation, you choose a training assignment strategy:
- Microsoft training catalog: Select specific modules from Microsoft's built-in library (videos, interactive modules, micro-learning).
- No training: Run the simulation purely to measure baseline susceptibility.
- Assign training based on user behavior: The recommended approach. Users who clicked the link, opened the attachment, or entered credentials are assigned targeted modules relevant to the technique they fell for. Users who did not interact can still be assigned a short awareness module or no training, depending on your policy.
Training completion is tracked and surfaced in the simulation report. You can set a due date and send reminders.
Simulation Automations (Playbooks)
Microsoft ships pre-built payload automations (sometimes called playbooks) — ready-made recurring sequences grouped by technique. For example, a “Credential Harvest” automation rotates through several credential-harvest payloads on a schedule you define. Enabling a payload automation is a one-click action: pick the audience, the cadence (weekly/bi-weekly/monthly), and the technique category, and Defender handles the rest. This is the lowest-effort way to keep a continuous training program running.
Reports and Metrics
After a simulation completes, the report focuses on four metrics that matter for MS-102:
- Click rate — percentage of targeted users who clicked the link or opened the attachment.
- Compromise rate — percentage who completed the compromising action (entered credentials, granted OAuth consent, downloaded “malware”). Compromise rate is always ≤ click rate.
- Training completion rate — percentage of assigned users who finished their modules by the due date.
- Repeat offenders — users who fell for multiple simulations across campaigns. The Users tab ranks targeted users by number of compromises and lets you filter to repeat offenders for focused follow-up.
The Overview tab shows trends across all simulations: how click and compromise rates move over time, and how your tenant compares to the industry benchmark Microsoft publishes.
Simulation vs. AIR — Do Not Confuse
A common MS-102 trap is conflating attack simulation training with Automated Investigation and Response (AIR). They are different features with different purposes:
| Attack simulation training | AIR | |
|---|---|---|
| Purpose | Educate users, measure susceptibility | Investigate and remediate real detections |
| Trigger | Admin-initiated, scheduled | Real threat detection (phish, malware, anomalies) |
| Action taken | Shows landing page, assigns training | Plays an investigation playbook, remediates entities |
| Real payload? | No | Yes — responds to actual threats |
Both live in the Defender portal, but AIR runs automatically against real alerts while simulation training is a planned, safe exercise.
Best Practices
- Pair every simulation with required training. A simulation without training only measures — it does not improve.
- Use automations for continuity. One-off tests are fine for baselines, but behavior change comes from regular, spaced exposure.
- Start gentle and escalate. Begin with obvious lures, then introduce harder-to-detect payloads as users improve.
- Track repeat offenders and escalate to managers or additional MFA requirements when warranted.
- Exclude service accounts, shared mailboxes, and executives' delegates unless those are explicitly in scope.
You are asked to enable recurring credential-harvest simulations against all staff with no admin intervention each cycle. Which feature should you configure?
Which licensing is required for a user to be targeted by attack simulation training?
After a credential-harvest simulation, which metric is always less than or equal to the click rate?