Skip to content

Defender Attack Simulator: strengths and limits

Microsoft Defender for Office 365 ships with its own phishing simulation and awareness platform. In some areas it is very good. In others, structural limits appear very quickly. This is a deliberately balanced look at both sides.

A woman at a two-monitor desk rests her chin on her hand, weighing up a printed comparison sheet lying in front of her
In this article

Microsoft Defender for Office 365 includes its own phishing simulation and awareness platform, Attack Simulation Training. Because it sits deep inside Microsoft 365, many organizations assume it is the logical choice for phishing simulations and employee awareness.

And honestly: in some areas it is very good. But there is another side that organizations should understand before they replace a specialized awareness platform with it.

This article is intentionally balanced. There are clear advantages — and there are structural limitations that become visible very quickly in larger or more mature security environments.

The positive side of Defender Attack Simulator

The advantages below are real, but they are not necessarily unique selling points: other providers may offer similar features or benefits.

Deep Microsoft 365 integrationTightly connected with M365, Exchange Online, Defender for Endpoint, Active Directory / Entra ID and Microsoft Sentinel — and with the right license, it comes for free.
Faster operational responseBlocking a malicious domain, sender or URL happens in one place. Administrators investigate, block, automate, quarantine and monitor without switching vendor consoles.
Native SOAR and automationReported phishing can trigger automated actions: email recall, mailbox cleanup, incident escalation, remediation workflows.
Combined endpoint and email visibilityWith Defender for Endpoint, organizations correlate email activity, endpoint activity, browser behavior, malicious connections and identity events.
Lower complexity for Microsoft customersLess vendor management, fewer integrations, fewer external platforms, simpler licensing alignment — everything from one shop.
Centralized security operationsIncidents, awareness campaigns, alerts, endpoint telemetry, email analysis and automation sit inside one broader security ecosystem.

Interim conclusion: the strength of the Microsoft Attack Simulator lies in its integration into the Microsoft Defender stack, especially with Microsoft Sentinel. For an organization with the size, structure and system landscape to benefit from operational consolidation, that is a genuine advantage.

The weak side of Defender Attack Simulator

What follows looks at one thing only: improving the risk behavior of employees, and the Attack Simulator as the product Microsoft offers for that purpose. These are the challenges we identified in use.

1No closed-loop learning systemSimulations stop at click detection, credential submission and a basic assignment. Sustainable improvement needs adaptive learning, reinforcement, behavioral repetition and long-term cycles.
2High operator workloadCampaign management, targeting, scheduling, reporting interpretation, training coordination and campaign closing across multiple AD tenants are time consuming.
3Limited realizm of simulationsCampaigns still rely on templates with basic customization, while real attacks use AI-generated language, supplier impersonation and multi-stage interaction.
4Weak reporting for behaviorReporting focuses on click and compromise rates. Reporting behavior, hesitation patterns, repeat behavior, learning progression and long-term trends stay invisible.
5No domain management & controlOnly limited flexibility for dedicated phishing domains, reputation management, landing pages and sender infrastructure. Static simulation domains render campaigns ineffective and unrealiztic.
6No MSSP / multi-tenant modelThe tooling is designed around individual tenant operation — a major limitation for MSSPs, managed SOC providers and companies running several AD domains.
7Limited training systemTraining rests on built-in modules with limited customization options; the product stays heavily simulation-focused.
8No local-cloud or on-prem choiceIt runs only in the Microsoft cloud. Hybrid infrastructure, regulatory restrictions or on-premise dependencies run into limitations.

Simulation alone will never solve poor risk behavior

This is not only a Microsoft problem — it affects large parts of the awareness industry. The narrative that trained users alone stop phishing attacks is unrealiztic. Without strong technical controls such as advanced email filtering, endpoint protection, browser security, identity protection and automated detection, users would be completely overwhelmed. Especially with AI-generated phishing, technical detection becomes more important again, not less.

The other half is the harder one. Companies implement technological safeguards through systems relatively quickly. Fostering sound risk behavior among people is a much more time-consuming endeavour — and conventional awareness does not help in this regard.

Pros and cons at a glance

There are third-party products that integrate very well into existing system architectures, which can largely offset the advantage of Microsoft's tight integration into its own stack. CYBERDISE Behavioral Defense Engineering (BDE) was specifically designed and built for such scenarios. The comparison below follows the points covered in this article.

Operationally strong inside the Microsoft ecosystem.Microsoft Defender Attack Simulator
Built for the scenarios the limitations on the left describe.Cyberdise Behavioral Defense Engineering
Learning model
No closed-loop learning system

Stops after click detection, credential submission and a basic user assignment.

Closed-loop learning

Continuous adaptive learning, reinforcement and long-term learning cycles.

Realizm of simulations
Templates with basic customization

Campaigns still feel standardized next to modern real-world phishing.

Custom, contextual exercises

Personalized and sophisticated scenarios rather than a template library.

Behavioral reporting
Click and compromise rates

Functional, but limited compared to specialized awareness analytics.

Behavioral intelligence

Reporting behavior, hesitation and repeat patterns, learning progression, long-term trends.

Domain control
No domain management & control

Limited flexibility for phishing domains, reputation, landing pages and sender infrastructure.

Own attack domains

Dedicated domains and landing pages under the program's own control.

Multi-tenant operation
No MSSP / multi-tenant model

Primarily designed around individual tenant operation.

MSSP / multi-tenant model

Built for multiple AD domains, managed SOC providers and multi-customer operation.

Deployment
Microsoft cloud only

Hybrid, regulated or on-premise environments run into limitations.

Local-cloud or on-prem choice

Deployment follows the regulatory and infrastructure situation, not the vendor's.

Conclusion

Microsoft Defender Attack Simulator is operationally strong inside the Microsoft ecosystem. But organizations should not confuse phishing simulations with complete security awareness maturity — or with people who actually demonstrate good risk behavior.

It is up to the procuring organization to decide which aspects of cyber security are a priority for it. The fact is that in the age of AI, attacks are far more sophisticated and occur far more quickly. But while companies can control and master the technological side relatively quickly, doing so with people is a much more protracted endeavour.

Those who want a more provocative reading will find another article on the same product.

Is Defender Attack Simulator included in Microsoft 365 E5?
It is part of Microsoft Defender for Office 365, and with the right license it comes for free. That, together with the deep integration into the Microsoft stack, is the main reason many organizations choose it.
Where does Defender Attack Simulator reach its limits?
In everything that goes beyond running a simulation: closed-loop learning, operator workload in larger environments, the realizm of template-based campaigns, behavioral reporting, control over phishing domains, multi-tenant operation, the breadth of the training system, and deployment outside the Microsoft cloud.
Does it support MSSP or multi-tenant operation?
Microsoft's awareness tooling is primarily designed around individual tenant operation, and large-scale multi-tenant awareness management is not one of its strengths. That is a major limitation for MSSPs, managed SOC providers and companies running several AD domains, and it drives operator workload at every stage.

See what closed-loop behavioral defense looks like next to a simulation tool.

Book a DemoCompare all features

Sources

  1. Microsoft Defender Attack Simulator: Strengths, Weaknesses and the Reality of Security AwarenessCyberdise AG
  2. Microsoft Defender Attack Simulator - What is Wrong With It?Cyberdise AG

Written by

Sebastian Münster

Chief Product Officer

Chief Product Officer (CPO), Co-Founder at Cyberdise AG, part of a leadership team with more than 30 years of experience in the infosec industry.