Study guide
Technical reference and lesson notes
Purpose of This Lesson
This lesson focuses on Attack Simulation Training in the Microsoft Defender portal. This feature allows security teams to run safe phishing simulations against users, measure who interacts with simulated phishing messages, and assign training based on user behavior.
For the SC-200 Microsoft Security Operations Analyst exam, this topic matters because it connects directly to real-world security operations work: phishing awareness, user risk reduction, email security monitoring, incident prevention, and post-simulation reporting.
A security operations analyst may not always be the person launching phishing campaigns, but they should understand how simulations support detection improvement, user education, and organizational resilience against credential theft and phishing attacks.
Key Concepts
Attack Simulation Training Overview
Attack Simulation Training is a Microsoft Defender for Office 365 feature used to simulate common phishing and social engineering attacks.
The goal is not to harm users or steal credentials. The goal is to safely test whether users recognize suspicious messages and to provide training when users fall for the simulation.
Attack simulations can help answer questions such as:
- Are users likely to click phishing links?
- Are users likely to submit credentials to a fake login page?
- Which departments, roles, or groups need more training?
- Are repeat offenders improving over time?
- Is the organization’s phishing awareness program effective?
This is a proactive security awareness and measurement feature, not a malware detonation tool or incident response tool.
Licensing Requirement
Attack Simulation Training requires the appropriate Microsoft Defender for Office 365 licensing.
The important SC-200 concept is:
- Microsoft Defender for Office 365 Plan 2 includes Attack Simulation Training.
- Microsoft 365 E5 commonly includes Defender for Office 365 Plan 2 capabilities.
For exam purposes, if the scenario involves phishing simulations, user training, payloads, and simulation reporting, think Defender for Office 365 Plan 2 / Attack Simulation Training.
Portal Location
Attack Simulation Training is accessed from the Microsoft Defender portal.
Typical navigation path:
- Open the Microsoft Defender portal.
- Go to Email & collaboration.
- Select Attack simulation training.
- Use the available tabs such as:
- Overview
- Simulations
- Automations
- Payloads / Content library
- Training
- Settings
The exact portal layout can change, but the feature is generally associated with Email & collaboration because it focuses heavily on phishing and email-based attacks.
Simulations
A simulation is a controlled phishing campaign created by the security team.
A simulation usually includes:
- Attack technique
- Payload
- Target users or groups
- Exclusions
- Training assignment settings
- Landing page
- End-user notifications
- Launch schedule
- End date
- Reporting
The analyst or security admin can create a simulation to test a specific social engineering scenario.
Attack Techniques
One common simulation technique is credential harvesting.
In a credential harvesting simulation, the user receives an email that attempts to convince them to click a link and enter credentials into a fake login page.
The point of the simulation is to determine whether the user:
- Receives the message
- Opens the message
- Clicks the link
- Submits credentials
- Reports the message
- Deletes, replies to, or forwards the message
For SC-200, recognize that credential harvesting simulations are meant to test user response to phishing attempts that target usernames and passwords.
Payloads
A payload is the simulated phishing message sent to users.
Payloads may imitate common real-world lures, such as:
- Password reset requests
- Account verification notices
- Financial service alerts
- Package delivery notifications
- Document sharing invitations
- HR or benefits messages
Microsoft provides built-in payloads, and organizations may also create custom payloads.
Important payload details include:
- Subject line
- Sender appearance
- Message body
- Link destination
- Landing page behavior
- Brand or service being impersonated
- Difficulty level
- Language and localization
For the exam, remember that the payload is the actual simulated phishing content delivered to the user.
Sending a Test Payload
Before launching a simulation broadly, an admin can send a test message to themselves or a small review group.
This is useful for validating:
- How the message appears in the mailbox
- Whether formatting looks correct
- Whether links behave as expected
- Whether the landing page is appropriate
- Whether the campaign is likely to meet the training objective
In a real production environment, this should still follow the organization’s approval process. Even a test phishing message can create confusion if it is not coordinated properly.
Target Users and Groups
A simulation can be assigned to selected users, groups, or potentially a broader population.
Targeting options may include:
- Specific users
- Groups
- Imported email address lists
- All users in the organization
A key detail from the lesson is that guest users are not treated the same as internal organization users for this type of simulation targeting.
From a SOC perspective, targeting should be deliberate. You would not usually run a broad phishing campaign without approval, communication planning, and leadership awareness.
Exclusions
Attack Simulation Training allows the creator to exclude certain users or groups from the campaign.
Exclusions may be needed for:
- Executives
- Legal or HR users
- Help desk staff
- Users on leave
- Sensitive business groups
- Users already in active incident response scenarios
- Test accounts
- Break-glass or administrative accounts
For SC-200, remember that targeting and exclusions help scope the simulation safely.
Training Assignments
One of the major benefits of Attack Simulation Training is that it can assign training based on user behavior.
For example, if a user clicks a phishing link or submits credentials during the simulation, the system can direct the user to training content.
Training may include:
- Microsoft-provided training modules
- Custom training assignments
- Due dates
- Reminders
- Educational landing pages
This turns the phishing test into a learning workflow instead of just a “gotcha” exercise.
Landing Pages
A landing page is what the user sees after interacting with the simulated phishing message.
For example, if the user clicks a phishing link, they may be redirected to a page explaining that the email was part of a security simulation.
A good landing page should:
- Explain what happened
- Avoid shaming the user
- Provide practical phishing identification tips
- Direct the user to assigned training
- Reinforce secure behavior
Landing pages can often be customized with organizational branding, messaging, and training guidance.
End-User Notifications
Attack Simulation Training can send notifications related to the campaign.
Examples include:
- Training assignment notifications
- Reminder messages
- Positive reinforcement messages
- Campaign-related communication
The lesson highlights that Microsoft provides default notification options.
From a real-world perspective, notifications should be reviewed carefully so users understand what they need to do and why.
Scheduling and Campaign Duration
A simulation can be launched immediately or scheduled for a later time.
Common scheduling decisions include:
- When the simulation starts
- How long it runs
- Whether timing should respect the user’s regional time zone
- Whether payloads should be removed from user inboxes after the simulation ends
Campaign duration matters because it affects how much time users have to interact with the message and how reporting is interpreted.
Simulation Reporting
After the simulation launches, reports show how users responded.
Common report metrics include:
- Users who received the message
- Users who clicked the link
- Users who supplied credentials
- Users who read the message
- Users who deleted the message
- Users who replied
- Users who forwarded the message
- Compromise rate
- Training completion status
For SC-200, understand that simulation reporting helps the security team measure user susceptibility and training effectiveness.
Automations
Attack Simulation Training also includes automation capabilities.
Automations can run simulations using specific techniques and payloads when certain conditions are met.
For example, an organization may automate recurring phishing simulations to continuously test users and measure improvement over time.
Do not confuse Attack Simulation Training automation with Microsoft Sentinel automation rules or Logic Apps playbooks. They are different automation concepts used in different parts of the Microsoft security ecosystem.
Content Library
The content library contains reusable simulation assets.
Examples include:
- Payloads
- Training content
- Landing pages
- Simulation templates
The content library helps security teams avoid building every campaign from scratch.
Settings: Repeat Offenders and Training Thresholds
Attack Simulation Training includes settings that influence how users are classified and trained.
Two important examples are:
Repeat Offender Threshold
This setting determines how many simulations a user must fail before being flagged as a repeat offender.
For example, if the threshold is set to two, a user may be considered a repeat offender after failing two simulations in a row.
Training Threshold
This setting controls how soon a completed training module can be reassigned to the same user.
For example, if a user already completed a training module recently, the system may avoid assigning the same module again until the configured threshold has passed.
These settings help reduce redundant training and identify users who may need additional coaching.
Microsoft Security Operations Context
How This Fits Into a SOC Workflow
Attack Simulation Training is part of a broader security operations strategy.
A SOC analyst may use simulation results to help identify:
- Departments with higher phishing susceptibility
- Users who repeatedly submit credentials
- Training gaps
- Business units that need targeted awareness campaigns
- Patterns that could inform detection tuning
- Opportunities to improve reporting workflows
This is not the same as investigating a live phishing incident. However, it supports incident prevention by improving user behavior before a real attack occurs.
How an Analyst Might Use This Feature
Triage
If simulation results show a high click rate, the SOC may treat that as a risk signal. It does not mean a real compromise occurred, but it may indicate that users are vulnerable to similar real-world attacks.
Investigation
Analysts can review which users interacted with simulated phishing messages and what actions they took.
Scope and Impact
Simulation reports help identify whether risk is concentrated in a small group, a department, or across the organization.
Containment and Remediation
Attack Simulation Training itself is not usually a containment tool. Instead, it supports remediation through user education and training.
Escalation
Results may need to be escalated to:
- Security leadership
- Compliance teams
- HR or training teams
- Department managers
- Identity and access management teams
Documentation
The SOC should document the purpose, scope, outcome, and follow-up actions from each simulation.
Detection Improvement
Simulation outcomes can influence future security controls, such as:
- Phishing reporting workflows
- Email security policies
- User awareness campaigns
- Conditional Access improvements
- Defender for Office 365 tuning
- SOC playbook updates
Exam-Relevant Takeaways
For the SC-200 exam, remember these points:
- Attack Simulation Training is part of Microsoft Defender for Office 365 Plan 2.
- It is used to safely test user susceptibility to phishing and social engineering.
- It is found under Email & collaboration in the Microsoft Defender portal.
- A simulation is the overall campaign.
- A payload is the phishing message or lure sent to users.
- A landing page is what users see after interacting with the simulated phishing message.
- Training can be assigned to users who fall for the simulation.
- Reports show metrics such as users compromised, links clicked, credentials submitted, and training status.
- Simulations can target users or groups and can include exclusions.
- Attack Simulation Training is not the same as Microsoft Sentinel analytics rules, automation rules, or playbooks.
- This feature supports prevention and awareness, not live incident containment.
- Results can be used to improve security awareness programs and future detection strategy.
Tool / Feature Decision Guide
| Scenario | Best Microsoft Security Tool or Feature | Why |
|---|---|---|
| You need to test whether users click phishing emails | Attack Simulation Training | It safely sends simulated phishing campaigns and tracks user behavior. |
| You need to train users who failed a phishing simulation | Attack Simulation Training with assigned training | The feature can assign training based on simulation results. |
| You need to investigate a real malicious email delivered to users | Microsoft Defender for Office 365 Explorer / incidents / alerts | Real email investigation requires Defender for Office 365 investigation tools, not a simulation. |
| You need to detect suspicious activity across multiple Microsoft security products | Microsoft Defender XDR incidents | Defender XDR correlates alerts and evidence across products. |
| You need to run scheduled KQL-based detections from connected log data | Microsoft Sentinel analytics rules | Sentinel analytics rules generate alerts/incidents from query logic. |
| You need to automate response actions after an incident is created in Sentinel | Microsoft Sentinel automation rules or playbooks | Automation rules manage incident-level automation; playbooks use Logic Apps for workflow actions. |
| You need to build a custom phishing payload for awareness testing | Attack Simulation Training payload library | Payloads define the simulated phishing content. |
| You need to see who clicked, submitted credentials, or completed training | Attack Simulation Training reports | Reports provide campaign outcome metrics. |
| You need to exclude specific executives or sensitive users from a simulation | Attack Simulation Training exclusions | Exclusions reduce operational risk and scope the campaign. |
| You need to block a real malicious sender, URL, or file | Defender allow/block controls or security policy, depending on scenario | Blocking real threats is a security enforcement workflow, not a phishing simulation. |
KQL Notes
This lesson does not focus on KQL.
Attack Simulation Training is primarily a Defender portal feature used for phishing simulation, reporting, and training assignment. You should not assume that every SC-200 topic requires KQL.
However, in the broader SC-200 exam, KQL is important for Microsoft Sentinel and advanced hunting scenarios. If simulation-related email data is exported or connected to a log source, a security team might analyze phishing trends with queries, but that is outside the core workflow covered in this lesson.
Key Exam Point
Use KQL when the scenario involves querying log data, hunting across tables, or building detection logic. Use Attack Simulation Training when the scenario is about safely testing users with simulated phishing campaigns and assigning training.
Common Exam Traps
Confusing Attack Simulation Training with Real Incident Response
Attack Simulation Training is for controlled phishing simulations. It is not used to contain an active phishing attack.
If the question describes a real malicious email campaign, look for Defender for Office 365 investigation and remediation tools instead.
Confusing Payloads with Malware
In this context, a payload is the simulated phishing email content. It is not necessarily malware or an exploit payload.
Choosing Sentinel When the Scenario Is User Phishing Training
Microsoft Sentinel is used for SIEM/SOAR workflows, analytics rules, KQL queries, incidents, and automation. If the scenario is specifically about sending phishing simulations and assigning training, the better answer is Attack Simulation Training.
Ignoring Licensing
Attack Simulation Training is associated with Defender for Office 365 Plan 2 capabilities. If licensing is part of the question, do not assume every Microsoft 365 tenant has this feature.
Forgetting About Scope and Exclusions
A simulation should be scoped carefully. Targeting all users without considering exclusions can create operational problems.
Treating Simulation Failure as Confirmed Compromise
If a user submits credentials during a simulation, that indicates risky behavior. It does not mean a real attacker obtained credentials.
The appropriate response is training, reporting, and risk reduction, not necessarily incident containment.
Confusing Attack Simulation Automations with Sentinel Automation
Attack Simulation Training automations are for simulation workflows. Sentinel automation rules and playbooks are used for incident automation and response workflows.
Real-World SOC Analyst Notes
Use Change Control for Production Simulations
In a real client environment, phishing simulations should be approved before launch.
A production simulation can affect:
- User trust
- Help desk volume
- Executive visibility
- HR and compliance processes
- Business operations
- Security awareness reporting
Even though the simulation is safe, it is still a planned security campaign.
Avoid Shaming Users
The goal is behavior improvement, not embarrassment.
A good program focuses on:
- Education
- Reinforcement
- Measurable improvement
- Practical phishing recognition skills
Punitive programs may reduce trust and discourage users from reporting suspicious emails.
Coordinate With the Help Desk
Phishing simulations may generate tickets or user questions. The help desk should know how to respond without spoiling the campaign.
A SOC or security team may provide the help desk with approved language, escalation instructions, and a point of contact.
Capture Useful Metrics
Useful metrics include:
- Total users targeted
- Delivery rate
- Click rate
- Credential submission rate
- Report rate
- Training completion rate
- Repeat offenders
- Department-level trends
- Improvement over time
These metrics can support security awareness reporting and risk management.
Watch for Tenant-Wide Impact
Sending a simulation to all users can have broad impact. Start with smaller pilot groups when appropriate.
Consider testing:
- IT/security pilot users
- A small business unit
- New employees
- High-risk departments
- Users with repeated phishing failures
Preserve Context for Future Reviews
Each simulation should have documentation showing:
- Why the simulation was run
- Who approved it
- Which users or groups were targeted
- Which users or groups were excluded
- What payload was used
- When the campaign started and ended
- What training was assigned
- What results were observed
- What follow-up actions were taken
Understand the Difference Between Awareness and Enforcement
Attack Simulation Training improves user behavior. It does not replace technical controls such as:
- Anti-phishing policies
- Safe Links
- Safe Attachments
- Microsoft Defender for Office 365 alerts
- Conditional Access
- MFA
- Identity Protection
- Email authentication controls
- Incident response playbooks
A mature security program uses both awareness training and technical enforcement.
Quick Reference Summary
- Attack Simulation Training is used to run safe phishing simulations.
- It is part of Defender for Office 365 Plan 2 capabilities.
- The feature is located in the Defender portal under Email & collaboration.
- A simulation is the overall phishing test campaign.
- A payload is the simulated phishing email.
- A landing page educates users after they interact with the simulation.
- Training can be assigned to users who fail the simulation.
- Reports show clicks, credential submissions, training completion, and compromise rate.
- Exclusions allow sensitive users or groups to be left out of a campaign.
- Automations can help run recurring or condition-based simulations.
- Simulation results support security awareness and prevention.
- This is different from investigating or remediating a real phishing attack.
- For real incidents, use Defender for Office 365 investigation tools and Defender XDR incidents.
- For KQL detection logic and SIEM workflows, use Microsoft Sentinel.
Flashcards
Q: What is Attack Simulation Training used for?
A: It is used to run safe phishing simulations, measure user behavior, and assign training to users who fall for simulated attacks.
Q: Which Defender product is Attack Simulation Training most closely associated with?
A: Microsoft Defender for Office 365 Plan 2.
Q: Where is Attack Simulation Training found in the Microsoft Defender portal?
A: Under Email & collaboration.
Q: What is a simulation?
A: A controlled phishing campaign that includes the attack technique, payload, target users, training, landing page, schedule, and reporting.
Q: What is a payload in Attack Simulation Training?
A: The simulated phishing email or lure sent to users.
Q: What does a credential harvesting simulation test?
A: Whether users will click a phishing link and submit credentials to a fake sign-in page.
Q: What is the purpose of a landing page?
A: To educate users after they interact with a simulated phishing message.
Q: Why are exclusions important?
A: They allow the security team to avoid targeting certain users or groups, reducing operational or business risk.
Q: What kind of reporting does Attack Simulation Training provide?
A: Metrics such as message received, link clicked, credentials submitted, training completed, and compromise rate.
Q: Is Attack Simulation Training used to contain a real phishing attack?
A: No. It is used for simulation and awareness training, not live incident containment.
Q: What tool should you think of for KQL-based detections and SIEM workflows?
A: Microsoft Sentinel.
Q: What is a repeat offender threshold?
A: A setting that determines how many failed simulations classify a user as a repeat offender.
Q: Why should phishing simulations use change control in production?
A: They can affect users, help desk volume, reporting, and business operations.
Q: What is the difference between a phishing simulation and a Defender for Office 365 phishing investigation?
A: A simulation is planned and safe; an investigation deals with real suspicious or malicious email activity.
Q: What is the main SC-200 decision point for this topic?
A: Use Attack Simulation Training when the scenario is about phishing awareness testing and training, not incident response or KQL detection.
Practice Questions
Question 1:
A security manager wants to test whether users will click a fake password reset email and submit credentials to a simulated sign-in page. Users who fail should receive training automatically. Which Microsoft feature should be used?
A. Microsoft Sentinel analytics rule
B. Microsoft Defender for Office 365 Attack Simulation Training
C. Microsoft Defender for Cloud regulatory compliance dashboard
D. Microsoft Entra Conditional Access
Correct Answer:
B. Microsoft Defender for Office 365 Attack Simulation Training
Explanation:
Attack Simulation Training is designed for safe phishing simulations, including credential harvesting scenarios and training assignments.
Question 2:
You are configuring a phishing simulation and need to define the email message that users will receive. Which component are you configuring?
A. Landing page
B. Payload
C. Workbook
D. Watchlist
Correct Answer:
B. Payload
Explanation:
The payload is the simulated phishing email content sent to users. It includes the lure, message body, and link behavior.
Question 3:
A company wants to run a phishing simulation but exclude executives and help desk staff from the campaign. Which configuration area is most relevant?
A. Exclusions
B. KQL query filters
C. Data connectors
D. Entity mapping
Correct Answer:
A. Exclusions
Explanation:
Exclusions are used to remove specific users or groups from the simulation scope.
Question 4:
After a phishing simulation, the security team wants to know who clicked the link, who submitted credentials, and who completed training. Where should they look?
A. Microsoft Sentinel watchlists
B. Attack Simulation Training reports
C. Microsoft Defender for Cloud recommendations
D. Microsoft Entra audit logs only
Correct Answer:
B. Attack Simulation Training reports
Explanation:
Simulation reports provide campaign outcome metrics, including clicks, credential submissions, and training status.
Question 5:
A real phishing email has been delivered to multiple users, and the SOC needs to investigate and remediate the message. Which statement is most accurate?
A. Use Attack Simulation Training because it handles all phishing investigations.
B. Use Defender for Office 365 investigation tools and Defender XDR incident workflows.
C. Use Attack Simulation Training automations to delete the message.
D. Use a phishing landing page to contain the incident.
Correct Answer:
B. Use Defender for Office 365 investigation tools and Defender XDR incident workflows.
Explanation:
Attack Simulation Training is for planned simulations and awareness training. Real phishing incidents require investigation and response using Defender for Office 365 and Defender XDR workflows.