2026-08-10 · 12 min read · Security Hardening

Master Phishing Simulation Setup with Azure & M365 Defender

A digital fish hook catching a stylized email icon, representing phishing simulation and cybersecurity training.

Phishing remains one of the most persistent and effective attack vectors against organizations. Proactive defense isn't just about technical controls; it's about empowering your users. Setting up effective phishing simulation campaigns using Azure and Microsoft 365 Defender allows you to test user resilience, identify vulnerable points, and deliver targeted training before a real attack compromises your systems. This guide provides a direct, CLI-first approach to configuring your environment and launching robust phishing simulations, ensuring your organization builds a stronger human firewall.

Prerequisites

Step 1: Verify Administrative Permissions & Module Installation

Before initiating any configuration, confirm that your administrative account possesses the necessary roles and that the required PowerShell modules for managing Azure AD and Exchange Online are installed. This ensures you have the authority and tools to perform all subsequent steps.

# Check current user's Azure AD roles
Connect-MsolService
Get-MsolRole -RoleName 'Security Administrator' | Get-MsolRoleMember

# Install Azure AD PowerShell module (if not already installed)
Install-Module -Name AzureAD -Scope CurrentUser -Force

# Install Exchange Online PowerShell module (if not already installed)
Install-Module -Name ExchangeOnlineManagement -Scope CurrentUser -Force

# Connect to Exchange Online PowerShell
Connect-ExchangeOnline -UserPrincipalName admin@yourdomain.com -ShowProgress $true

Connect-MsolService: Establishes a connection to Microsoft Online Services.

Get-MsolRole -RoleName 'Security Administrator' | Get-MsolRoleMember: Retrieves members of the 'Security Administrator' role. We recommend this role over 'Global Administrator' for least privilege principles.

Install-Module -Name AzureAD -Scope CurrentUser -Force: Installs the Azure AD module for managing users and groups.

Install-Module -Name ExchangeOnlineManagement -Scope CurrentUser -Force: Installs the modern Exchange Online module.

Connect-ExchangeOnline -UserPrincipalName admin@yourdomain.com -ShowProgress $true: Connects to Exchange Online using your administrator account.

Portal alternative: To check roles in the Azure portal, navigate to 'Azure Active Directory' > 'Roles and administrators' and search for 'Security Administrator'. Click on it to see assigned members. Module installation is CLI-only.

Expected result: Your administrative account is listed as a member of 'Security Administrator' (or 'Global Administrator'), and all modules install successfully, allowing you to connect to Azure AD and Exchange Online.

Common pitfall: Attempting to install modules without elevated PowerShell permissions or encountering certificate trust errors. Ensure PowerShell is run as Administrator. For certificate errors, check your execution policy (`Set-ExecutionPolicy RemoteSigned`).

Step 2: Strategize Your Phishing Campaign

Before diving into technical configurations, it's crucial to define the strategic aspects of your phishing simulation. A well-planned campaign ensures relevance, effectiveness, and accurate measurement of your security posture. This step is foundational and entirely conceptual.

# No direct CLI command for strategy; this is a planning phase.
# Document your strategy diligently. Example:
# New-Item -Path C:\PhishingSims -Name "CampaignStrategy.txt" -ItemType File
# Add-Content -Path C:\PhishingSims\CampaignStrategy.txt -Value "Campaign Name: Q3 Spear Phishing Test`nObjective: Measure susceptibility to credential harvesting`nTarget Group: All Marketing & Sales Staff`nAttack Technique: Credential Harvest`nPayload: Fake Microsoft 365 login page`nTraining Focus: Recognizing malicious URLs & MFA importance`nStart Date: 2026-09-01`nEnd Date: 2026-09-15"

New-Item and Add-Content are provided as examples for documenting your strategy in a text file, though any document management system is suitable.

Portal alternative: This step is entirely conceptual and typically involves discussions, whiteboard sessions, and documentation creation outside of any specific portal. Record your decisions in a shared document or project management tool.

Expected result: A clearly documented plan outlining your campaign's objectives, target audience, chosen attack technique (e.g., credential harvest, malware attachment, drive-by URL), specific payloads, and the corresponding training content. This document will guide subsequent technical steps.

Step 3: Prepare Target User Groups in Azure AD

To precisely target your phishing simulation campaigns and manage recipient lists efficiently, create or identify specific Azure AD security groups. This ensures your simulation reaches the intended audience without affecting unintended users and simplifies reporting.

# Connect to Azure AD if not already connected
Connect-AzureAD

# Create a new security group for your simulation target (if needed)
New-AzureADGroup -DisplayName "Phishing Simulation - Q3 Marketing" -MailEnabled $false -SecurityEnabled $true -Description "Target group for Q3 phishing simulation campaign for Marketing"

# Add users to the new security group (replace with actual UPNs)
$users = @("user1@yourdomain.com", "user2@yourdomain.com")
$groupId = (Get-AzureADGroup -DisplayName "Phishing Simulation - Q3 Marketing").ObjectId
foreach ($user in $users) {
    $userId = (Get-AzureADUser -ObjectId $user).ObjectId
    Add-AzureADGroupMember -ObjectId $groupId -RefObjectId $userId
}

# Verify group members
Get-AzureADGroupMember -ObjectId $groupId | Select-Object DisplayName, UserPrincipalName

New-AzureADGroup: Creates a new Azure AD security group.

Add-AzureADGroupMember: Adds specified users to the newly created group.

Get-AzureADGroupMember: Retrieves members of a specific Azure AD group.

Portal alternative: In the Azure portal, navigate to 'Azure Active Directory' > 'Groups' > 'New group'. Select 'Security' as the Group type, provide a name and description, then add members. You can also manage existing groups from this section.

Expected result: A dedicated Azure AD security group populated with the specific users targeted for your phishing simulation campaign. This group will be referenced when configuring the simulation.

Step 4: Whitelist Simulation Sources in Exchange Online

To prevent your legitimate phishing simulation emails from being quarantined or blocked by internal Exchange Online filters (such as ATP/Defender for Office 365), you must configure mail flow rules. This is critical for ensuring deliverability and accurate reporting of user behavior.

# Connect to Exchange Online if not already connected
Connect-ExchangeOnline -UserPrincipalName admin@yourdomain.com -ShowProgress $true

# Define simulator properties (replace with your simulator's actual details)
$simulatorIPs = @("192.0.2.1", "198.51.100.2") # Example IP addresses
$simulatorDomains = @("phishingsimulator.com", "another-sim.net") # Example domains

# Create a transport rule to bypass spam filtering for simulation emails
New-TransportRule -Name "Bypass Spam Filtering for Phishing Simulations" `
    -FromAddresses $simulatorDomains `
    -SenderIpRanges $simulatorIPs `
    -SetSCL -1 `
    -StopRuleProcessing $true `
    -Comments "Rule to allow phishing simulation emails to bypass spam filtering."

# (Optional, but recommended) Create a rule to bypass Zero-hour Auto Purge (ZAP)
# Note: ZAP bypass for *specific conditions* is generally handled by Advanced Delivery Policy (Step 5).
# For very specific scenarios where ZAP must be bypassed via transport rule, consider conditions carefully.
# A simpler approach for *general* whitelisting is the one above + Advanced Delivery.

New-TransportRule: Creates a new mail flow rule in Exchange Online.

-FromAddresses: Specifies the sending domains of your phishing simulation platform.

-SenderIpRanges: Specifies the sending IP addresses of your phishing simulation platform.

-SetSCL -1: Sets the Spam Confidence Level to -1, effectively bypassing spam filtering.

-StopRuleProcessing $true: Ensures no other rules process these emails, preventing conflicts.

Portal alternative: In the Microsoft 365 admin center, navigate to 'Exchange admin center' > 'Mail flow' > 'Rules'. Click 'Add a rule', choose 'Create a new rule...', and configure conditions (e.g., 'The sender' > 'IP address is in any of these ranges or exactly matches' and 'The sender' > 'domain is') and actions ('Set the spam confidence level (SCL) to' > '-1').

Expected result: Mail flow rules are created in Exchange Online that explicitly allow emails from your phishing simulation platform's IP addresses and domains to bypass spam filtering and deliver directly to user inboxes, ensuring simulation emails are not blocked.

Step 5: Configure Advanced Delivery Policy for Third-Party Simulators

If you're utilizing a third-party phishing simulation platform, setting up an Advanced Delivery policy in Microsoft 365 Defender is paramount. This policy correctly categorizes these simulations, preventing them from being blocked by Defender for Office 365 features like ZAP (Zero-hour Auto Purge) and ensuring they don't impact your security posture metrics negatively.

# Connect to Security & Compliance Center PowerShell (if not already connected)
Connect-IPPSSession -UserPrincipalName admin@yourdomain.com -ShowProgress $true

# Define third-party simulator details (replace with your actual data)
$simTenantId = "a1b2c3d4-e5f6-7890-1234-567890abcdef" # Your tenant ID
$simName = "Third-Party Phishing Platform"
$simURL = @("sims.phishingservice.com", "training.phishingprovider.net") # Simulation URLs
$simDomain = @("phishing-sender.com", "secure-training.org") # Sending domains
$simIP = @("203.0.113.10", "198.18.0.5") # Sending IPs

# Create or update the Advanced Delivery Phish Simulation Override policy
Set-AdvancedDeliveryPhishSimulationOverride -Identity $simTenantId `
    -Name $simName `
    -PhishSimulationURL $simURL `
    -PhishSimulationSendingDomains $simDomain `
    -PhishSimulationIPs $simIP

Connect-IPPSSession: Connects to the Security & Compliance Center PowerShell, required for advanced delivery cmdlets.

Set-AdvancedDeliveryPhishSimulationOverride: Configures the advanced delivery policy for phishing simulations. If an override for your tenant ID doesn't exist, this command will create it; otherwise, it updates it.

-Identity $simTenantId: Your Microsoft 365 tenant ID, which uniquely identifies your organization.

-Name $simName: A friendly name for your third-party simulator configuration.

-PhishSimulationURL: A list of URLs used in your simulation emails that point to landing pages or malicious content.

-PhishSimulationSendingDomains: A list of email sending domains used by your third-party simulator.

-PhishSimulationIPs: A list of sending IP addresses used by your third-party simulator.

Portal alternative: In the Microsoft 365 Defender portal, navigate to 'Email & collaboration' > 'Policies & rules' > 'Threat policies' > 'Advanced delivery'. Under the 'Phishing simulation' tab, click 'Add' or 'Edit' to configure your third-party simulation settings.

Expected result: An Advanced Delivery policy is successfully configured in Microsoft 365 Defender, classifying emails and URLs from your specified third-party phishing simulation platform as legitimate simulations, preventing false positives and ensuring accurate reporting.

Common pitfall: Incomplete or incorrect IP addresses, domains, or URLs. Even a single missing value can cause your simulations to be blocked. Always double-check this information with your third-party vendor's documentation.

Step 6: Plan and Build the Phishing Simulation Campaign (M365 Defender AST)

With your environment prepared, it's time to design the actual phishing simulation campaign within Microsoft 365 Defender's Attack Simulation Training (AST). While some setup elements can be managed via PowerShell, the comprehensive building of the campaign — including selecting attack techniques, crafting email payloads, configuring landing pages, and associating training modules — is primarily an interactive process best done through the Defender portal for its rich UI and template library.

# While full campaign creation is GUI-driven, you can list existing simulations via PowerShell:
# (Note: Requires connecting to Security & Compliance Center PowerShell first, as in Step 5)
Get-AttackSimulation

Get-AttackSimulation: Retrieves details about existing phishing simulation campaigns configured in Microsoft 365 Defender. This command is useful for auditing and verification.

Portal alternative (Primary Method): In the Microsoft 365 Defender portal, navigate to 'Email & collaboration' > 'Attack simulation training'. Click 'Simulations' > 'Launch a simulation'. Follow the wizard:

  1. Select technique: Choose 'Credential Harvest', 'Malware Attachment', 'URL for Malware Attachment', 'Link in attachment', 'Drive-by URL', 'OAuth Consent Grant', or 'Operation X'. We typically recommend 'Credential Harvest' for initial broad campaigns.
  2. Name simulation: Provide a descriptive name and description.
  3. Select payload and login page: Choose from existing payloads/templates or create a custom one. Craft a compelling email subject and body. Select an appropriate landing page (e.g., a fake Microsoft login page).
  4. Target users: Select the Azure AD security group prepared in Step 3.
  5. Assign training: Link relevant training modules from Microsoft's library or your custom content.
  6. Select simulation logic: Define criteria for repeating attacks or assigning training immediately.
  7. Review: Check all settings before launching.

Expected result: A fully configured phishing simulation campaign within M365 Defender AST, with a chosen attack technique, a crafted email payload, a designated landing page, and associated training modules ready to be launched against your target user group.

Step 7: Launch and Monitor the Phishing Simulation

Once your phishing simulation campaign is meticulously planned and built, the next step is to launch it and actively monitor its progress. This ensures it reaches the intended targets, helps you identify any unforeseen issues, and allows for the initial collection of engagement data.

# Launching a specific campaign is primarily a GUI action within M365 Defender.
# However, you can monitor the status of all simulations via PowerShell.
# (Note: Requires connecting to Security & Compliance Center PowerShell first)
Get-AttackSimulation | Select-Object Name, CreationTime, LastModifiedTime, Status, AttackTechnique, `
    @{Name='TargetUsers'; Expression={$_.Payload.TargetUsers | Out-String}}, `
    @{Name='LandingPage'; Expression={$_.Payload.LandingPageUrl}}

Get-AttackSimulation: Used here to retrieve and display key details about all simulations, including their current status (e.g., 'Running', 'Completed', 'Scheduled').

Portal alternative (Primary Method for Launch): In the Microsoft 365 Defender portal, navigate to 'Email & collaboration' > 'Attack simulation training' > 'Simulations'. Select your prepared simulation and click 'Launch simulation'. After launching, monitor its progress on the 'Overview' tab or within the specific simulation's details page.

Expected result: The phishing simulation campaign is successfully launched, and emails are being delivered to the target group. You can observe the status changing from 'Scheduled' to 'Running' and begin to see initial user engagement data populate within the Defender portal.

Common pitfall: Rushing the launch. Always perform a test run with a small, internal group if possible to catch any issues with email rendering, landing page functionality, or tracking before a broad release. Pay attention to delivery issues in the logs.

Step 8: Analyze Simulation Results and Generate Reports

After the simulation concludes or runs for a sufficient period, the crucial phase of analysis begins. This involves collecting and interpreting comprehensive simulation data to identify vulnerable users, understand common click patterns, and measure the effectiveness of your security awareness programs.

# Connect to Security & Compliance Center PowerShell if not already connected
Connect-IPPSSession -UserPrincipalName admin@yourdomain.com -ShowProgress $true

# Get detailed results for a specific simulation (replace with actual Simulation ID or Name)
# Find Simulation ID using: (Get-AttackSimulation).SimulationId
$simulationId = (Get-AttackSimulation -Name "Phishing Simulation - Q3 Marketing").SimulationId

# Get overall results for the simulation
Get-AttackSimulationReport -SimulationId $simulationId

# Get user-specific compromise information
Get-AttackSimulationUserReport -SimulationId $simulationId | Select-Object UserPrincipalName, `
    @{'Name'='Compromised'; Expression={$_.UserStatus -eq 'Compromised'}}, `
    PhishClicked, LandingPageVisited, DataSubmitted, Trained

Get-AttackSimulationReport: Provides aggregate data for a specified simulation, including overall compromise rates, user actions, and training completion.

Get-AttackSimulationUserReport: Retrieves detailed information for each user participating in the simulation, indicating their specific actions (e.g., clicked the link, entered credentials, completed training).

-SimulationId: The unique identifier for your phishing simulation campaign.

Portal alternative: In the Microsoft 365 Defender portal, navigate to 'Email & collaboration' > 'Attack simulation training' > 'Simulations'. Click on your completed simulation. The 'Report' tab provides a rich, interactive dashboard with overall metrics, user-specific data, and insights into behaviors. You can also export reports from here.

Expected result: Detailed reports showing which users fell for the simulation (e.g., clicked a link, entered credentials), which users visited the landing page, and who completed the associated training. This data will inform your remediation and future training efforts.

Step 9: Implement Post-Simulation Remediation & Training

The final and arguably most important step is to act on the insights gained from your simulation. This involves providing targeted training for users who fell for the simulation, reinforcing security awareness across the organization, and adjusting future security policies or controls based on identified vulnerabilities. This is an ongoing process.

# While direct "remediation" is mostly policy/training, you can use PowerShell to identify users
# for follow-up actions (e.g., assigning specific training modules in a learning platform).
# Example: Identify compromised users for a follow-up email.
$simulationId = (Get-AttackSimulation -Name "Phishing Simulation - Q3 Marketing").SimulationId
$compromisedUsers = Get-AttackSimulationUserReport -SimulationId $simulationId | Where-Object {$_.UserStatus -eq 'Compromised'} | Select-Object UserPrincipalName

# Output the list of compromised users to a file for further action
$compromisedUsers | Export-Csv -Path "C:\PhishingSims\CompromisedUsers_Q3.csv" -NoTypeInformation

# (Conceptual, depends on your learning platform's API/PowerShell module)
# Foreach ($user in $compromisedUsers) {
#     Invoke-LearningPlatformAPI -Action AssignTraining -User $user.UserPrincipalName -Training "Advanced Phishing Recognition"
# }

Where-Object {$_.UserStatus -eq 'Compromised'}: Filters the user report to identify only those who fell for the simulation.

Export-Csv: Exports the list of compromised users to a CSV file for easy follow-up.

Portal alternative: Within the Microsoft 365 Defender portal, navigate to 'Email & collaboration' > 'Attack simulation training' > 'Simulations'. In the report for your simulation, identify compromised users. The AST platform automatically assigns training to users who fall for a simulation if configured in Step 6. For broader communication, you would use your internal communication channels (email, Teams announcements) and your learning management system (LMS) for custom or supplemental training.

Expected result: A clear plan for targeted intervention is in place. Compromised users receive specific, often automated, security awareness training. General security awareness is reinforced across the organization, and insights from the simulation inform adjustments to security policies, technical controls, or future simulation strategies.

When to bring in a consultant

While M365 Defender's Attack Simulation Training is powerful, its full potential can be complex to unlock. DIY phishing simulations often fall short due to common issues: inaccurate whitelisting leading to blocked emails, poorly crafted payloads that aren't convincing, incorrect scope, or, critically, misinterpreting results and failing to implement effective follow-up. If your organization lacks dedicated security awareness staff, struggles with PowerShell scripting, or needs to develop a sophisticated, ongoing security awareness program integrated with broader security strategies, bringing in an expert is highly recommended. SkyCore Solutions can design, implement, and manage your phishing simulation campaigns, ensuring maximum impact with minimal internal overhead, and help you translate simulation data into actionable security improvements.

Book a free consultation