What is Microsoft 365 attack simulation training?
It is Microsoft's built-in phishing simulation feature, part of Defender for Office 365 Plan 2, managed from the Defender portal at security.microsoft.com under Email & collaboration, then Attack simulation training. Admins launch simulated phishing campaigns against their own tenant and assign Microsoft's training modules to people who click.
If you searched for where the feature lives in the admin portal and landed here: Defender portal, not the Microsoft 365 admin centre, and if the menu entry is absent your tenant does not carry the licence for it. The feature itself is real and capable, and for organisations already paying for E5 it is the obvious first experiment. Whether it is the right long-term programme is the rest of this page, and the programme fundamentals it plugs into are covered in our phishing simulation guide.
What does the Microsoft simulator do well?
Three things: authenticity, integration and price-if-you-already- pay. Payloads mirror real campaigns Microsoft observes, delivery happens natively inside the tenant, and for an E5 organisation the marginal cost is zero. For security teams living in the Defender portal, it is right there.
Those strengths are why our honest advice to genuine E5 shops with admin capacity is: run it, at least as a baseline. The considerations that push organisations elsewhere are not about the simulator's quality; they are about who it was built for. It assumes a security team that lives in Defender, an all-Microsoft environment, and a licence tier most small and mid-sized businesses do not hold.
Where are the limits?
Four practical ones: the licence wall (Defender for Office 365 Plan 2 or E5 only), thinner awareness-training content than dedicated platforms, admin complexity aimed at security professionals, and reporting designed for the SOC rather than for auditors and insurers.
| Factor | M365 attack simulation | Dedicated platform |
|---|---|---|
| Licence needed | Defender for Office P2 / E5 | Any mailbox, any plan |
| Works outside Microsoft 365 | No | Yes, including Google Workspace |
| Training content | Simulation-linked modules | Full course library, role-based |
| Custom templates | Yes, security-admin tooling | Yes, built for non-specialists |
| Compliance evidence | SOC-style reporting | Audit and insurer-ready exports |
| Runs itself | Assumes a security team | Automation-first, small-team friendly |
The licence wall is the decisive row for most smaller organisations: upgrading every seat to E5 to obtain one feature costs far more than a dedicated platform, a comparison the cost guide makes concrete. And phishing simulation alone is half a programme; the training layer around it is what changes behaviour, per the complete guide.
When is a dedicated platform the better fit?
When you are not on E5, when nobody owns the Defender portal, when you need audit and insurer evidence, or when training content matters as much as simulation. In practice that describes most businesses under a few hundred seats.
train2secure sits squarely in that lane: phishing simulation plus a full training library in one per-seat price, published openly, running on any email environment, with insurer-ready evidence exports and automation that assumes no dedicated security team. The wider vendor field, Microsoft included, is compared fairly in the alternatives guide; the fastest way to see the difference is to run the free phishing test against your own team.
Common questions
Where is attack simulation training in the 365 admin portal?
In the Microsoft Defender portal (security.microsoft.com) under Email & collaboration, then Attack simulation training. It does not live in the general Microsoft 365 admin centre, which is where most people look first. If the menu item is missing, your tenant lacks the required licence.
What licence do you need for Microsoft attack simulation training?
Microsoft Defender for Office 365 Plan 2, which comes with Microsoft 365 E5 or as an add-on. Business Basic, Standard and Premium tenants do not include it, which is why many small businesses cannot find the feature at all.
Is Microsoft attack simulation training good?
Genuinely, within its lane: realistic payloads, tight Outlook integration and no extra vendor. Its weaknesses are the licence gate, thinner awareness training content than dedicated platforms, and reporting built for security teams rather than compliance evidence.
Can you run phishing simulations without E5?
Yes, with a dedicated platform: they send simulations to any mailbox over standard email, so they work on Business plans, Google Workspace and mixed environments alike. That is usually cheaper than upgrading every seat to E5 for one feature.
Do insurers and auditors accept M365 simulation reports?
Simulation data helps, but insurers and auditors usually want the full picture: training completion records, certificates and policy evidence alongside phishing results. Dedicated platforms produce that bundle in one export, which is exactly the gap they exist to fill.
Compare the full market in the alternatives guide or check the numbers in the cost guide.
