Attack Simulation Training Learning Path

Learn how to use Attack Simulation Training to strengthen phishing resilience through safe, measurable simulations.

What you will learn

Simulation planning, payload selection, targeting, training assignments, measurement, and follow-up.

Implementation and governance

Run simulations responsibly, protect employee trust, avoid public shaming, and measure improvement rather than click rates alone.

Recommended podcast episodes

Continue learning

Return to the Microsoft Defender Learning Hub for the complete path, or use the M365.fm Learning Hub to explore another domain.

Last reviewed: July 2026.

Learning objectives

  • Use simulations to identify risky user behaviors and learning needs.
  • Align awareness activities with real threat scenarios.
  • Measure improvement without turning security training into a blame exercise.

FAQ

What should happen after a simulation?

Use the results to improve guidance, controls, and targeted training. The purpose is to build resilience, not to rank or punish individuals.

Continue learning: Defender for Office 365.