Home › Blog › Phishing training
Security · 24 September 2026 · 12 min read
Every security product in Microsoft 365 is built on the assumption that some phishing will reach a human. What that human does next decides whether the company has an incident. This is the training that works: five habits, one reporting button, a quarterly test with the results fed back, and no shaming — who runs it, how, how often, and which Microsoft tools carry most of the weight.
Phishing training, in one table
| Question | Answer |
|---|---|
| Who trains | One named owner — the IT lead, or the person who owns security — with HR for onboarding and managers to reinforce; an outside partner for the simulations and the debrief |
| How | Thirty minutes at onboarding, a two-minute reminder a month, a simulated attack a quarter with training assigned on the spot to whoever fell for it, and a Report button in Outlook that someone answers |
| How often | Onboarding for everyone new; simulations quarterly; a refresh a year; an extra round after any real incident, using the real message |
| What to measure | The report rate, not only the click rate: the share of people who report the test is the number that should rise |
| The tools | Report Message in Outlook; Safe Links and Safe Attachments in Defender for Office 365 Plan 1; attack simulation training in Defender for Office 365 Plan 2; multi-factor authentication under Conditional Access in Entra ID P1; all of it inside Business Premium or Microsoft 365 E3 with Plan 2 as the add-on |
| What it protects | The bank account, the customer list, the tenant — and the sale price and the insurance premium that depend on them |
Companies spend on mail filters, endpoint protection and identity controls, and rightly: they stop most of what arrives. Then one message gets through — a shared document from a colleague’s real name, a supplier invoice with new bank details, a voicemail notification, an HR notice that needs a signature by Friday — and an employee decides in three seconds whether it is real. Everything the company owns now lives in that decision: the account-takeover field report shows what four days of a compromised mailbox cost. Training does not replace the controls; it is the control the others were designed around.
Training that lists twenty warning signs produces people who remember none. Training that installs five habits produces people who act on them without thinking, which is the point, because the attacker is counting on nobody thinking.
The five habits, and the attack each one stops
| Habit | What it looks like | What it stops |
|---|---|---|
| Pause on urgency | “Today”, “overdue”, “your account will be closed”, a director who needs something in the next ten minutes: the urgency is the attack. Anything that cannot wait one phone call is suspicious because it cannot wait one phone call. | Chief-executive fraud, fake invoices, MFA-fatigue prompts at odd hours |
| Read the real address, not the name | The display name says the colleague; the address underneath says otherwise. On a phone, tap the name to see it. A real partner whose mailbox was taken over shows a real address, which is why the next habits matter too. | Lookalike domains, spoofed display names |
| Never sign in from a link | A page that asks for a Microsoft password was reached by a link in an email: close it. Sign in through the bookmark or the app instead and see whether the document is really there. This one habit defeats the proxy kits that relay the MFA prompt. | Credential harvest, adversary-in-the-middle phishing |
| Check the link before the click | Hover on a computer, press and hold on a phone, and read the domain from the right: the part before the first single slash, and the last two pieces of it. microsoft.com.secure-login.net is secure-login.net. Shortened links and QR codes in email are not followed at all. | Drive-by pages, QR-code phishing, link-in-attachment |
| Report; do not delete | The Report button in Outlook sends the message to the people who can pull it from every other mailbox and block the sender. Deleting it protects one person; reporting it protects the company. Nobody is ever criticised for a false alarm. | The second, third and fortieth recipient |
Most training says “hover over the link” and stops. What people see when they hover is a long string they do not know how to read, so they click anyway. The rule that works: find the first single slash after https://; everything before it is the address; the last two pieces of that address, separated by a dot, are the domain, and the domain is the only part that means anything. login.microsoftonline.com is Microsoft. microsoftonline.com.login-verify.co is login-verify.co, whatever it says at the front. Long strings of random characters, a domain that ends in something unfamiliar, a link that goes to a file-sharing service you do not use, a link whose text says one address and whose target says another: all of these are reasons not to click, and none of them are reasons to feel stupid for asking.
Two special cases are worth their own sentence in training. A QR code in an email or a PDF exists to move the click to a personal phone, outside the company’s link scanning and device policies; it is never scanned from a message. And a link that has already been rewritten by Safe Links — it starts with a Microsoft address and contains the original — is a sign the tenant is protected, not that the link is safe; the check at click time happens after the click, and a page that then asks for a password is still closed.
An attachment is a link that runs. Word and Excel files that ask to “enable content” or “enable editing to view” are asking to run a macro; the answer is no, always, and a real document does not need it. HTML attachments open a sign-in page on the local machine where no filter can see it. Archive files — zip, ISO, IMG — hide what is inside from the scanner. An invoice from a supplier who has never sent one that way, or whose invoices normally come from a system rather than a person, is a phone call. Safe Attachments opens each file in a sandbox before delivery, which removes most of the risk, and the training removes the rest.
Training also has to cover the day after the click, because the person who fell for it is the first person able to notice, and often the only one for days. The signs are ordinary and worth listing on a card:
The instruction that goes with the list is short: tell IT immediately, do not change the password yourself first, and do not reply to anyone in the thread. A password change without revoking sessions and removing the attacker’s authenticator changes nothing; that is IT’s job, in the right order, and it is what our incident response and hardening does when the company has no one to do it.
A phishing simulation against your own staff, run inside Microsoft Defender in three weeks: who clicked, who entered a password, who reported it — and the hardening list that follows. From €1,200.
The owner is one named person — the IT lead, or whoever owns security — and the programme fails without one. HR runs the onboarding module because HR sees every new starter; managers reinforce it because a reminder from the person who signs the timesheet lands differently from one from IT; finance gets its own extra rule, below. What the owner should not do is run the simulations alone: the pretext that is fair, the group that is representative, the debrief that moves budget without embarrassing anyone — those are judgement, and an outside partner who has run fifty of them is cheaper than learning on your own staff. That is what a phishing simulation service is for.
Nobody trains by shaming. A leaderboard of who clicked produces people who hide their mistakes, and hidden mistakes are the four-day dwell time in the field report. The person who clicks and reports within the minute is the success story of the programme, and should be told so.
Training stops most phishing. Two process rules stop the money leaving when training fails: a change of bank details is verified by phone on a number already on file, never on a number in the email; and a payment over a threshold needs two people. Written down, signed by the owner, and nobody is ever criticised for making the call. The most expensive incidents we have investigated would have ended at that phone call.
What carries the weight, and where it lives
| Tool | What it does for training | Where it comes from |
|---|---|---|
| Report Message | The button in Outlook and on the phone that makes the fifth habit possible; reported mail can be pulled from every mailbox and the sender blocked | Every plan; switched on and pointed at a mailbox someone reads |
| Safe Links and Safe Attachments | Links checked at the click, attachments opened in a sandbox first, impersonation of your own executives flagged; the training covers what these miss | Defender for Office 365 Plan 1: in Business Premium and, since July 2026, in Microsoft 365 E3 |
| Attack simulation training | The quarterly test: real pretexts, Microsoft’s landing pages, per-person results, training assigned automatically to whoever fell for it | Defender for Office 365 Plan 2: in Microsoft 365 E5; an add-on elsewhere, with a ninety-day trial that covers the first campaign |
| Conditional Access | Makes a harvested password worthless: managed devices required, MFA registration protected, phishing-resistant sign-in for finance and administrators | Entra ID P1: in Business Premium and Microsoft 365 E3; risk-based policies in Entra ID P2 |
| Defender for Business or Endpoint | Contains the click that ran something before it spreads | Defender for Business in Business Premium; Defender for Endpoint in the enterprise suites |
| Intune | The phone that scanned the QR code is a managed device with app protection, or it has no access to company mail at all | Intune: in Business Premium and Microsoft 365 E3 |
For an organisation under three hundred seats, every row above except attack simulation is inside Business Premium; the simulation needs Plan 2 or the trial. For a larger one, Microsoft 365 E3 carries the same and Microsoft 365 E5 adds the simulation, the risk-based sign-in and the investigation tooling. The licence is the smaller part; switching the controls on and running the programme is the work.
Three things, in the order an owner cares about them. It stops the incidents that cost real money — the redirected invoice, the ransomware weekend, the customer list on a leaver’s laptop. It answers the questions an insurer and an auditor ask — do staff receive phishing awareness training, is it tested, how often — with a report instead of a slide. And it changes what a buyer’s due-diligence team writes about the company, which changes the price. A trained workforce is the cheapest security control there is, and the only one that gets better with use.
Conditional Access, Safe Links, the Report button, Intune on the phones — configured in report-only mode first so nobody is locked out, then the programme above, run with you. Tell us the headcount and the plan you are on.
No. Habits decay in weeks; a two-minute monthly reminder with a real example and a quarterly simulation keep them alive at almost no cost. The annual session is the refresh, not the programme.
Tell them the company runs simulations and why; never tell them when. Announced tests measure attention that day, not behaviour.
First campaigns commonly land in double digits; the number matters less than the direction over the next two rounds and the share of people who report. A report rate that climbs is the programme working.
Yes: the onboarding is HR's, the reminders take an hour a month from one person, and the simulation, the report and the hardening are what we do as a service.
Business Premium under three hundred seats, Microsoft 365 E3 above it; add Defender for Office 365 Plan 2 for the simulations, or use its ninety-day trial for the first one.