Offensive testing

Phishing simulations

Build a campaign, choose targets, track clicks, and report user risk back to the client.

8 min read
Phishing hook lifting an email beside a security checkmark

Before you start

Simulations send real email into the client's tenant, so the sending identity must be permitted to send. The Campaign readiness check on the page verifies the tenant connection and the Microsoft Graph send permissions before you launch, and tells you exactly which permission is missing if it fails.

Create a campaign

  1. 1Go to Phishing sims and click New campaign.
  2. 2Name the campaign and pick the tenant it runs against.
  3. 3Choose a template — credential harvest, invoice lure, MFA fatigue or a custom body you write yourself.
  4. 4Select targets from the tenant's mailboxes, or bulk-import a list of addresses.
  5. 5Launch. Each recipient gets a uniquely tokenised link so clicks are attributed to the individual.

Track results

The campaign view shows sent, opened, clicked and reported counts, plus a per-user table. Click-through is the headline number clients care about; repeat clickers are the training priority.

Adding targets and deleting a campaign

Campaigns are editable after launch.

  1. 1Use Add targets to include new starters or a department you missed; they receive the same template.
  2. 2Use Delete campaign to permanently remove a campaign and its tracking data once you have exported the results.