Simulate a phishing attack with Attack simulation training - Microsoft Defender for Office 365 (original) (raw)

In Attack simulation training in Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2, simulations are benign cyberattacks that you run in your organization. These simulations test your security policies and practices, as well as train your employees to increase their awareness and decrease their susceptibility to attacks. This article walks you through creating a simulated phishing attack using Attack simulation training.

For getting started information about Attack simulation training, see Get started using Attack simulation training.

To launch a simulated phishing attack, do the following steps:

  1. In the Microsoft Defender portal at https://security.microsoft.com, go to Email & collaboration > Attack simulation training > Simulations tab. Or, to go directly to the Simulations tab, use https://security.microsoft.com/attacksimulator?viewid=simulations.
  2. On the Simulations tab, select Launch a simulation to start the new simulation wizard.
    The Launch a simulation button on the Simulations tab in Attack simulation training in the Microsoft Defender portal

The following sections describe the steps and configuration options to create a simulation.

Note

At any point after you name the simulation during the new simulation wizard, you can select Save and close to save your progress and continue later. The incomplete simulation has the Status value Draft. You can pick up where you left off by selecting the simulation and then selecting the Edit simulation action that appears.

On the Select technique page, select an available social engineering technique:

* This social engineering technique allows you to use QR codes. For more information, see the QR code simulations and training section later in this article.

If you select the View details link in the description, a details flyout opens that describes the technique and the simulation steps that result from the technique.

For more information about the different social engineering techniques, see Simulations.

The Details flyout for the credential harvest technique on the Select technique page

When you're finished on the Select technique page, select Next.

Name and describe the simulation

On the Name simulation page, configure the following settings:

When you're finished on the Name simulation page, select Next.

Select a payload and login page

On the Select payload and login page page, you need to select an existing payload or create a new payload to use.

For the Credential Harvest or Link in Attachment social engineering techniques, you can also view the login page that's used in the payload, select a different login page to use, or create a new login page to use.

Select a payload

The Select payload and login page page has two tabs:

The following information is shown for each payload:

You can sort the entries by clicking on an available column header.

To find a payload in the list, type part of the payload name in the Search box and then press the ENTER key.

To filter the payloads, select Filter. The following filters are available in the Filters flyout that opens:

When you're finished configuring filters, select Apply, Cancel, or Clear filters.

If you select a payload by selecting the check box next to the name, a Send a test action appears above the list of payloads. Use this action to send a copy of the payload email to yourself (the currently logged in user) for inspection.

The Global payloads tab on the Select payload page with a payload selected and the Send a test action in Attack simulation training.

On the Tenant payloads tab, if no payloads are available or if you want to create your own payload, select Create a payload. The creation steps are the same as at Attack simulation training > Content library tab > Payloads > Tenant payloads tab. For more information, see Create custom payloads for Attack simulation training.

The Tenant payloads tab on the Select payload page with a payload selected and the Send a test action in Attack simulation training.

If you select a payload by clicking anywhere in the row other than the check box next to the name, details about the payload are shown in a flyout that opens:

The Payload tab in the payload details flyout in Attack simulation training in the Microsoft Defender portal

If the simulation doesn't use Credential Harvest or Link in Attachment payloads, or if you don't want to view or edit the login page that's used, select Next on the Select payload and login page page to continue.

To select the login page that's used in Credential Harvest or Link in Attachment payloads, go to the Select a login page subsection.

Select a login page

Note

The Login page tab is available only in the details flyout of Credential Harvest or Link in Attachment payloads.

On the Select payload and login page page, select the payload by clicking anywhere in the row other than the check box to open the details flyout for the payload.

In the details flyout of the payload, the Login page tab shows the login page that's currently selected for the payload.

To view the complete login page, use the Page 1 and Page 2 links at the bottom of the page for two-page login pages.

The login page tab in the payload details flyout in Attack simulation training in the Microsoft Defender portal

To change the login page that's used in the payload, select Change login page.

On the Select login page flyout that opens, the following information is shown for each login page:

To find a login page in the list, type part of the login page name in the Search box and then press the ENTER key.

Select Filter to filter the login pages by Source or Language.

The Select login page in the Login page tab in payload details flyout in Attack simulation training in the Microsoft Defender portal

To create a new login page, select Create new. The creation steps are the same as at Attack simulation training > Content library tab > Login pages > Tenant login pages tab. For instructions, see Create login pages.

Back on the Select login page, verify the new login page you created is selected, and then select Save.

Back on the payload details flyout, select Close.

When you're finished on the Select a payload and login page page, select Next.

Configure OAuth Payload

Note

This page is available only if you selected OAuth Consent Grant on the Select technique page and a corresponding payload.

On the Configure OAuth payload page, configure the following settings:

When you're finished on the Configure OAuth payload page, select Next.

Target users

On the Target users page, select who receives the simulation. Use the following options to select users:

When you're finished on the Target users page, select Next.

Exclude users

On the Exclude users page, you can select Exclude some of the targeted users from this simulation to exclude users that would otherwise be included based on your previous selections on the Target users page.

The methods to find and select users are the same as described in the previous section for Include only specific users and groups.

When you're finished on the Exclude users page, select Next.

Tip

If you selected How-to Guide as the social engineering technique, you go directly to the Select end user notification page.

Assign training

On the Assign training page, you can assign trainings for the simulation. We recommend that you assign training for each simulation, as employees who go through training are less susceptible to similar attacks.

Use the following options on the page to assign trainings as part of the simulation:

When you're finished on the Assign training page, select Next.

Training assignment

Note

This page is available only if you selected Select training courses and modules myself on the Assign training page.

On the Training assignment page, select the trainings that you want to add to the simulation by selecting Add trainings.

In the Add training flyout that opens, use the following tabs to select trainings to include in the simulation:

The option to add the recommended training on the Training assignment page in Attack simulation training in the Microsoft Defender portal

On either tab, the following information is shown for each training:

On either tab, you can use the Search box to find trainings. Type part of the training name and press the ENTER key.

On either tab, select one or more trainings by selecting the check box next to the training name. To select all trainings, select the check box in the Training name column header. When you're finished, select Add.

Back on the Training assignment page, the selected trainings are now listed. The following information is shown for each training:

The Training assignment page in Attack simulation training in the Microsoft Defender portal

When you're finished on the Training assignment page, select Next.

Select a landing page

On the Select phish landing page page, configure the web page that users are taken to if they open the payload in the simulation.

Select one of the following options:

When you're finished on the Selecting phish landing page page, select Next.

Select end user notifications

On the Select end user notification page, select from the following notification options:

When you're finished on the Select end user notification page, select Next.

Select a training assignment notification

Note

This page is available only if you selected Customized end user notifications on the Select end user notifications page.

The Training assignment notification page shows the following notifications and their configured languages:

These notifications are also available at Attack simulation training > Content library tab > End user notifications:

For more information, see End-user notifications for Attack simulation training.

Do one of the following steps:

When you're finished on the Training assignment notification page, select Next.

Select a training reminder notification

Note

This page is available only if you selected Customized end user notifications on the Select end user notifications page.

The Training reminder notification page shows the following notifications and their configured languages:

These notifications are also available at Attack simulation training > Content library tab > End user notifications:

For more information, see End-user notifications for Attack simulation training.

In Set frequency for reminder notification, select Weekly (the default value) or Twice a week, and then do one of the following steps:

When you're finished on the Training reminder notification page, select Next.

Select a positive reinforcement notification

Note

This page is available only if you selected Customized end user notifications on the Select end user notifications page.

You have the following options in the Delivery preferences section for positive reinforcement notifications:

When you're finished on the Positive reinforcement notification page, select Next.

Configure the simulation launch details

On the Launch details page, you choose when to start and end the simulation. We stop capturing interaction with this simulation after the end date you specify.

Choose one of the following values:

Configure the remaining options on the page:

When you're finished on the Launch details page, select Next.

Review simulation details

On the Review simulation page, you can review the details of the simulation.

Select the Send a test button to send a copy of the payload email to yourself (the currently logged in user) for inspection.

You can select Edit in each section to modify the settings within the section. Or you can select Back or the specific page in the wizard to modify the settings.

When you're finished on the Review simulation page, select Submit.

The Review simulation page in Attack simulation training in the Microsoft Defender portal

On the Simulation has been scheduled for launch page, you can use the links to go to the Attack simulation training overview or to view all payloads.

When you're finished on the Simulation has been scheduled for launch, select Done.

Back on the Simulations tab, the simulation that you created is now listed. The Status value depends on your previous selection in the Configure the simulation launch details step:

QR code simulations and training

You can select payloads with QR codes to use in simulations. The QR code replaces the phishing URL as the payload that's used in the simulation email message in the following social engineering techniques:

For more information about QR code payloads and configuring a custom QR code payload, see QR code payloads.

For more information about reporting for simulations with QR code payloads, see Reporting for QR code simulations.

View simulations

The Simulations tab in Attack simulation training at https://security.microsoft.com/attacksimulator shows any simulations that you created.

The following information is shown for each simulation. You can sort the simulations by clicking on an available column header. Select Customize columns to change the columns that are shown. By default, all columns are selected:

Tip

To see all columns, you likely need to do one or more of the following steps:

Use the Search box to search for the name of an existing simulation.

Select Filter to filter the simulations by Technique or Status (all Status values except for Excluded).

When you're finished configuring filters, select Apply, Cancel, or Clear filters.

To see simulations that have been excluded from reporting (the Status value is Excluded), use the Show excluded simulations toggle on the Simulations tab.

View simulation reports

For simulations with the Status value In progress or Completed, you can view the report for the simulation by using either of the following methods on the Simulations tab at https://security.microsoft.com/attacksimulator?viewid=simulations:

The title of the report page that opens shows the name of the simulation and other information (for example, the status, social engineering technique, and delivery status).

Tip

In the following scenarios, the report page opens, but no other information or actions are available on the page:

You can select View activity timeline to see date/time information about the simulation (simulation scheduled, simulation launched, simulation ended, and training due dates).

The rest of the report page contains tabs as described in the following subsections.

To close the simulation report, select Close.

Report tab

For a description of what's on the Report tab for simulations, see Simulation report for simulations.

Users tab

The Users tab contains the following information for each user in the simulation. You can sort the users by clicking on an available column header. Select Customize columns to change the columns that are shown. The default columns are marked with an asterisk (*):

Tip

To see all columns, you likely need to do one or more of the following steps:

To change the list of users from normal to compact spacing, select Change list spacing to compact or normal, and then select Compact list.

Select Filter to filter the targeted users by selecting one or more of the following values in the flyout that opens:

When you're finished configuring the filters, select Apply, Cancel, or Clear filters.

Use the Search box to find a user in the list by typing part of the name, and then press the ENTER key.

Details tab

The Details tab contains details about the simulation in the following sections:

Take action on simulations

All actions on existing simulations start on the Simulations tab. To go there, open the Microsoft Defender portal at https://security.microsoft.com, go to Email & collaboration > Attack simulation training > Simulations tab. Or, to go directly to the Simulations tab, use https://security.microsoft.com/attacksimulator?viewid=simulations.

Tip

To see the (Actions) control that's required to act on simulations on the Simulations tab, you likely need to do one or more of the following steps:

Copy simulations

You can copy an existing simulation and modify it to suit your needs. This action saves time and effort when you create new simulations based on previous ones.

You can copy any simulation that's available in the Simulations tab, regardless of the Status value. When you copy the simulation, you can change the setting in the new copy of the simulation. For example, change the simulation name, description, technique, payload, and target users.

To copy a simulation, do the following steps:

  1. On the Simulations tab at https://security.microsoft.com/attacksimulator?viewid=simulations, find and select the simulation to copy by selecting the check box next to the name.
  2. Select the Copy simulation action that appears on the tab.
  3. The simulation wizard opens with all the settings from the original simulation. The default simulation name on the Name simulation page is the original name plus the suffix _Copy.
  4. Review and modify the simulation configuration as needed. Select Submit to launch it or Save and close to review it later. If you select Cancel, the copied simulation isn't saved.

Cancel simulations

You can cancel simulations with the Status value In progress or Scheduled.

To cancel a simulation, do the following steps:

  1. On the Simulations tab at https://security.microsoft.com/attacksimulator?viewid=simulations, find and select the in-progress or scheduled simulation to cancel by selecting (Actions) at the end of the row.
  2. Select Cancel simulation, and then select Confirm in the confirmation dialog.

After you cancel the simulation, the Status value changes to Canceled.

Remove simulations

You can't remove simulations with the Status value In progress.

To remove a simulation, do the following steps:

  1. On the Simulations tab at https://security.microsoft.com/attacksimulator?viewid=simulations, find and select the simulation to remove by selecting (Actions) at the end of the row.
  2. Select Delete, and then select Confirm in the confirmation dialog.

After you remove the simulation, it no longer appears on the Simulations tab.

Exclude completed simulations from reporting

The Exclude action is available only for simulations with the Status value Competed.

By default, all completed simulations are included in reporting. To exclude a completed simulation from reporting, do the following steps:

  1. On the Simulations tab at https://security.microsoft.com/attacksimulator?viewid=simulations, find and select the completed simulation to exclude from reporting by selecting (Actions) at the end of the row.
  2. Select Exclude, and then select Confirm in the confirmation dialog.

After you exclude the completed simulation from reporting, the Status value changes to Excluded, and the simulation is no longer visible on the Simulations tab when the Show excluded simulations toggle is off .

To see completed simulations that have been excluded from reporting, use either of the following methods:

Include completed simulations in reporting

A simulation is excluded from reporting only if you exclude it as described in the previous section. The Include action is available only for simulations with the Status value Excluded, which are visible on the Simulations tab only when Show excluded simulations is toggled on .

To include a completed session in reporting after it has been excluded, do the following steps:

  1. On the Simulations tab at https://security.microsoft.com/attacksimulator?viewid=simulations, set the Show excluded simulations toggle to On.
  2. Select the simulation by clicking (Actions) at the end of the row, and then select Exclude.

After you included the excluded simulation, the Status value changes to Completed. Toggle Show excluded simulations to off to see the simulation.