Attack Simulation Training Learning Path
Learn how to use Attack Simulation Training to strengthen phishing resilience through safe, measurable simulations.
What you will learn
Simulation planning, payload selection, targeting, training assignments, measurement, and follow-up.
Implementation and governance
Run simulations responsibly, protect employee trust, avoid public shaming, and measure improvement rather than click rates alone.
Recommended podcast episodes
Continue learning
Return to the Microsoft Defender Learning Hub for the complete path, or use the M365.fm Learning Hub to explore another domain.
Last reviewed: July 2026.
Learning objectives
- Use simulations to identify risky user behaviors and learning needs.
- Align awareness activities with real threat scenarios.
- Measure improvement without turning security training into a blame exercise.
FAQ
What should happen after a simulation?
Use the results to improve guidance, controls, and targeted training. The purpose is to build resilience, not to rank or punish individuals.
Continue learning: Defender for Office 365.