Offensive testing
Phishing simulations
Build a campaign, choose targets, track clicks, and report user risk back to the client.
8 min read

Before you start
Simulations send real email into the client's tenant, so the sending identity must be permitted to send. The Campaign readiness check on the page verifies the tenant connection and the Microsoft Graph send permissions before you launch, and tells you exactly which permission is missing if it fails.
Create a campaign
- 1Go to Phishing sims and click New campaign.
- 2Name the campaign and pick the tenant it runs against.
- 3Choose a template — credential harvest, invoice lure, MFA fatigue or a custom body you write yourself.
- 4Select targets from the tenant's mailboxes, or bulk-import a list of addresses.
- 5Launch. Each recipient gets a uniquely tokenised link so clicks are attributed to the individual.
Track results
The campaign view shows sent, opened, clicked and reported counts, plus a per-user table. Click-through is the headline number clients care about; repeat clickers are the training priority.
Adding targets and deleting a campaign
Campaigns are editable after launch.
- 1Use Add targets to include new starters or a department you missed; they receive the same template.
- 2Use Delete campaign to permanently remove a campaign and its tracking data once you have exported the results.