20+ years with Microsoft 1,100+ organisations under management 131 countries invoiced locally 5 of 6 Solutions Partner designations 4-hour first response
IT Partner.Microsoft Solutions Partner +44 20 8142 5752 Talk to us Get a quote

HomeBlog › Phishing training

Security · 24 September 2026 · 12 min read

No filter stops the email a person is determined to open. Training is the control.

Every security product in Microsoft 365 is built on the assumption that some phishing will reach a human. What that human does next decides whether the company has an incident. This is the training that works: five habits, one reporting button, a quarterly test with the results fed back, and no shaming — who runs it, how, how often, and which Microsoft tools carry most of the weight.

Phishing training, in one table

QuestionAnswer
Who trainsOne named owner — the IT lead, or the person who owns security — with HR for onboarding and managers to reinforce; an outside partner for the simulations and the debrief
HowThirty minutes at onboarding, a two-minute reminder a month, a simulated attack a quarter with training assigned on the spot to whoever fell for it, and a Report button in Outlook that someone answers
How oftenOnboarding for everyone new; simulations quarterly; a refresh a year; an extra round after any real incident, using the real message
What to measureThe report rate, not only the click rate: the share of people who report the test is the number that should rise
The toolsReport Message in Outlook; Safe Links and Safe Attachments in Defender for Office 365 Plan 1; attack simulation training in Defender for Office 365 Plan 2; multi-factor authentication under Conditional Access in Entra ID P1; all of it inside Business Premium or Microsoft 365 E3 with Plan 2 as the add-on
What it protectsThe bank account, the customer list, the tenant — and the sale price and the insurance premium that depend on them

Companies spend on mail filters, endpoint protection and identity controls, and rightly: they stop most of what arrives. Then one message gets through — a shared document from a colleague’s real name, a supplier invoice with new bank details, a voicemail notification, an HR notice that needs a signature by Friday — and an employee decides in three seconds whether it is real. Everything the company owns now lives in that decision: the account-takeover field report shows what four days of a compromised mailbox cost. Training does not replace the controls; it is the control the others were designed around.

What a trained employee actually does: five habits

Training that lists twenty warning signs produces people who remember none. Training that installs five habits produces people who act on them without thinking, which is the point, because the attacker is counting on nobody thinking.

The five habits, and the attack each one stops

HabitWhat it looks likeWhat it stops
Pause on urgency“Today”, “overdue”, “your account will be closed”, a director who needs something in the next ten minutes: the urgency is the attack. Anything that cannot wait one phone call is suspicious because it cannot wait one phone call.Chief-executive fraud, fake invoices, MFA-fatigue prompts at odd hours
Read the real address, not the nameThe display name says the colleague; the address underneath says otherwise. On a phone, tap the name to see it. A real partner whose mailbox was taken over shows a real address, which is why the next habits matter too.Lookalike domains, spoofed display names
Never sign in from a linkA page that asks for a Microsoft password was reached by a link in an email: close it. Sign in through the bookmark or the app instead and see whether the document is really there. This one habit defeats the proxy kits that relay the MFA prompt.Credential harvest, adversary-in-the-middle phishing
Check the link before the clickHover on a computer, press and hold on a phone, and read the domain from the right: the part before the first single slash, and the last two pieces of it. microsoft.com.secure-login.net is secure-login.net. Shortened links and QR codes in email are not followed at all.Drive-by pages, QR-code phishing, link-in-attachment
Report; do not deleteThe Report button in Outlook sends the message to the people who can pull it from every other mailbox and block the sender. Deleting it protects one person; reporting it protects the company. Nobody is ever criticised for a false alarm.The second, third and fortieth recipient

Most training says “hover over the link” and stops. What people see when they hover is a long string they do not know how to read, so they click anyway. The rule that works: find the first single slash after https://; everything before it is the address; the last two pieces of that address, separated by a dot, are the domain, and the domain is the only part that means anything. login.microsoftonline.com is Microsoft. microsoftonline.com.login-verify.co is login-verify.co, whatever it says at the front. Long strings of random characters, a domain that ends in something unfamiliar, a link that goes to a file-sharing service you do not use, a link whose text says one address and whose target says another: all of these are reasons not to click, and none of them are reasons to feel stupid for asking.

Two special cases are worth their own sentence in training. A QR code in an email or a PDF exists to move the click to a personal phone, outside the company’s link scanning and device policies; it is never scanned from a message. And a link that has already been rewritten by Safe Links — it starts with a Microsoft address and contains the original — is a sign the tenant is protected, not that the link is safe; the check at click time happens after the click, and a page that then asks for a password is still closed.

Attachments

An attachment is a link that runs. Word and Excel files that ask to “enable content” or “enable editing to view” are asking to run a macro; the answer is no, always, and a real document does not need it. HTML attachments open a sign-in page on the local machine where no filter can see it. Archive files — zip, ISO, IMG — hide what is inside from the scanner. An invoice from a supplier who has never sent one that way, or whose invoices normally come from a system rather than a person, is a phone call. Safe Attachments opens each file in a sandbox before delivery, which removes most of the risk, and the training removes the rest.

The signs a mailbox has already been taken over

Training also has to cover the day after the click, because the person who fell for it is the first person able to notice, and often the only one for days. The signs are ordinary and worth listing on a card:

The instruction that goes with the list is short: tell IT immediately, do not change the password yourself first, and do not reply to anyone in the thread. A password change without revoking sessions and removing the attacker’s authenticator changes nothing; that is IT’s job, in the right order, and it is what our incident response and hardening does when the company has no one to do it.

Not sure where your people stand? Measure it before you train

A phishing simulation against your own staff, run inside Microsoft Defender in three weeks: who clicked, who entered a password, who reported it — and the hardening list that follows. From €1,200.

Book a simulation →

Who trains, and who does not

The owner is one named person — the IT lead, or whoever owns security — and the programme fails without one. HR runs the onboarding module because HR sees every new starter; managers reinforce it because a reminder from the person who signs the timesheet lands differently from one from IT; finance gets its own extra rule, below. What the owner should not do is run the simulations alone: the pretext that is fair, the group that is representative, the debrief that moves budget without embarrassing anyone — those are judgement, and an outside partner who has run fifty of them is cheaper than learning on your own staff. That is what a phishing simulation service is for.

Nobody trains by shaming. A leaderboard of who clicked produces people who hide their mistakes, and hidden mistakes are the four-day dwell time in the field report. The person who clicks and reports within the minute is the success story of the programme, and should be told so.

How: the programme that fits in a working year

  1. Onboarding, thirty minutes, in the first week. The five habits, the Report button, the card with the compromise signs, and one real example from the company’s own mail. Delivered by HR from a script, or by video with a two-question check.
  2. A two-minute reminder a month. One real phishing message the company received, anonymised, with what gave it away. Sent by the owner, three paragraphs. This is the part most programmes skip and the part that keeps the habits alive.
  3. A simulated attack a quarter. Run from inside Microsoft Defender against everyone, with a pretext agreed in advance, so nothing leaves the tenant. Whoever clicks lands on a short training page at that moment, not in a spreadsheet a month later. attack simulation explains what the report shows.
  4. Feedback within a week. The numbers by department, never by name outside HR, and the one thing to change. Report rate is the headline; click rate second; credential rate the one the board sees.
  5. A refresh a year, and an extra round after any real incident — using the real message, because nothing teaches like the one that actually arrived.

The extra rule for finance

Training stops most phishing. Two process rules stop the money leaving when training fails: a change of bank details is verified by phone on a number already on file, never on a number in the email; and a payment over a threshold needs two people. Written down, signed by the owner, and nobody is ever criticised for making the call. The most expensive incidents we have investigated would have ended at that phone call.

The Microsoft tools, and which plan they come in

What carries the weight, and where it lives

ToolWhat it does for trainingWhere it comes from
Report MessageThe button in Outlook and on the phone that makes the fifth habit possible; reported mail can be pulled from every mailbox and the sender blockedEvery plan; switched on and pointed at a mailbox someone reads
Safe Links and Safe AttachmentsLinks checked at the click, attachments opened in a sandbox first, impersonation of your own executives flagged; the training covers what these missDefender for Office 365 Plan 1: in Business Premium and, since July 2026, in Microsoft 365 E3
Attack simulation trainingThe quarterly test: real pretexts, Microsoft’s landing pages, per-person results, training assigned automatically to whoever fell for itDefender for Office 365 Plan 2: in Microsoft 365 E5; an add-on elsewhere, with a ninety-day trial that covers the first campaign
Conditional AccessMakes a harvested password worthless: managed devices required, MFA registration protected, phishing-resistant sign-in for finance and administratorsEntra ID P1: in Business Premium and Microsoft 365 E3; risk-based policies in Entra ID P2
Defender for Business or EndpointContains the click that ran something before it spreadsDefender for Business in Business Premium; Defender for Endpoint in the enterprise suites
IntuneThe phone that scanned the QR code is a managed device with app protection, or it has no access to company mail at allIntune: in Business Premium and Microsoft 365 E3

For an organisation under three hundred seats, every row above except attack simulation is inside Business Premium; the simulation needs Plan 2 or the trial. For a larger one, Microsoft 365 E3 carries the same and Microsoft 365 E5 adds the simulation, the risk-based sign-in and the investigation tooling. The licence is the smaller part; switching the controls on and running the programme is the work.

What it does for the business

Three things, in the order an owner cares about them. It stops the incidents that cost real money — the redirected invoice, the ransomware weekend, the customer list on a leaver’s laptop. It answers the questions an insurer and an auditor ask — do staff receive phishing awareness training, is it tested, how often — with a report instead of a slide. And it changes what a buyer’s due-diligence team writes about the company, which changes the price. A trained workforce is the cheapest security control there is, and the only one that gets better with use.

Switch the controls on, then train the people

Conditional Access, Safe Links, the Report button, Intune on the phones — configured in report-only mode first so nobody is locked out, then the programme above, run with you. Tell us the headcount and the plan you are on.

Get a quote →

Asked by the people who run it

Is an annual video enough?

No. Habits decay in weeks; a two-minute monthly reminder with a real example and a quarterly simulation keep them alive at almost no cost. The annual session is the refresh, not the programme.

Should we tell staff before a simulation?

Tell them the company runs simulations and why; never tell them when. Announced tests measure attention that day, not behaviour.

What click rate is normal?

First campaigns commonly land in double digits; the number matters less than the direction over the next two rounds and the share of people who report. A report rate that climbs is the programme working.

Can we run this without IT staff?

Yes: the onboarding is HR's, the reminders take an hour a month from one person, and the simulation, the report and the hardening are what we do as a service.

Which licence do we need?

Business Premium under three hundred seats, Microsoft 365 E3 above it; add Defender for Office 365 Plan 2 for the simulations, or use its ninety-day trial for the first one.

Worth reading next