Microsoft 365 Phishing Simulation: How to Test Your Team Without an E5 License
Microsoft's built-in Attack Simulator requires an M365 E5 or E5 Security licence. Here's how to run the same Microsoft-themed phishing test on any M365 plan using PhishSpark — with SPF/DKIM setup, Defender whitelisting, and step-by-step campaign setup.
Microsoft 365 includes a built-in phishing simulation tool called Attack Simulator (now part of Microsoft Defender for Office 365). It's well-integrated with the Microsoft ecosystem and easy to use — but there's a significant catch.
Attack Simulator requires an M365 E5 or E5 Security add-on licence. E5 costs $57 per user per month — more than twice the price of standard M365 Business Premium. For a 100-person company, that's an additional $68,400 per year just to access the phishing simulation feature.
If your organisation runs M365 Business Basic, Business Standard, or Business Premium, Attack Simulator is not available to you. And it's not worth upgrading your entire Microsoft licensing tier just for one security feature.
This guide covers how to run a fully functional Microsoft-themed phishing simulation using PhishSpark — on any M365 plan, without touching your Microsoft licensing.
What you need
- A Microsoft 365 subscription (any plan — Business Basic, Business Standard, Business Premium)
- Admin access to your Microsoft 365 tenant (for whitelisting the simulation IP in Defender)
- A domain to send from — your actual company domain or a lookalike
- A free PhishSpark account
Step 1: Set up your sending domain in PhishSpark
Go to Domains → Add Domain and enter your company domain (the one your employees receive email on — e.g. yourcompany.com).
PhishSpark generates three DNS records you need to add to your domain:
- SPF TXT record — add this to your domain root (
@). It authorises PhishSpark's sending IP (48.217.201.137) to send email from your domain. - DKIM TXT record — add this to a specific subdomain PhishSpark specifies. It enables cryptographic signing of every outgoing simulation email.
- DMARC TXT record — add this to
_dmarc.yourdomain.com. It tells receiving servers how to handle failed authentication.
If your domain DNS is managed through Microsoft 365 (via the Microsoft 365 admin centre's domain management), you can add these records from Microsoft 365 Admin Centre → Settings → Domains → Your domain → DNS records → Add record. If you use an external DNS provider like Cloudflare (recommended — propagation takes seconds), add them there.
After adding the records, click Verify in PhishSpark. The platform checks all three records automatically and shows you which passed.
Step 2: Create a Microsoft-themed email template
Go to Templates → New Template. Name your template something that includes "Microsoft" or "Office 365" — for example, "Microsoft 365 Password Expiry". This name matters: PhishSpark's phishing landing page automatically applies Microsoft branding (colour scheme, sign-in form design) when the template name contains "microsoft", "office", or "365".
For the email itself, a highly effective Microsoft 365 phishing template:
Subject: Action required: your Microsoft 365 password expires in 24 hours
HTML body: Use a realistic Microsoft-styled email with your company logo if you have it, the Microsoft blue (#0078d4), and a clear action button linking to {{PHISH_LINK}}. The body should greet the employee by first name ({{FIRST_NAME}}) and create urgency around password expiry or account security.
Place {{TRACKING_PIXEL}} at the bottom of the HTML body for open tracking.
Full HTML template examples for Microsoft 365 phishing emails are available in our phishing email templates guide.
Step 3: Whitelist PhishSpark's IP in Microsoft Defender for Office 365
This step is critical for M365 organisations. Microsoft Defender for Office 365 (included with Business Premium and above) automatically scans every link in every inbound email. If you don't whitelist the simulation IP, Defender will click your phishing tracking links within seconds of delivery — inflating your click rate to 100% before any human reads the email.
To whitelist in Microsoft Defender for Office 365:
- Go to the Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → Anti-phishing
- Edit your default anti-phishing policy
- Under "Trusted senders and domains", add PhishSpark's sending IP:
48.217.201.137 - Also navigate to Safe Links policy and add any simulation tracking domains to the "Do not rewrite the following URLs" list
If your organisation uses Exchange Online Protection (EOP) without the full Defender plan:
- Go to Exchange Admin Centre → Mail flow → Rules
- Create a new rule: "If sender IP is
48.217.201.137, bypass spam filtering" - Set action to "Modify the message properties → Set the spam confidence level (SCL) to −1 (bypass spam filtering)"
Wait 5 minutes for the policy to propagate before launching your campaign.
Step 4: Upload your M365 user list
Go to Target Lists → New List. Export your employee list from the Microsoft 365 Admin Centre: Users → Active users → Export users. The export includes display name, email, and department — exactly the columns PhishSpark expects.
Upload the CSV. PhishSpark maps the columns automatically. Including the department column means your results report will show click rates broken down by team — useful for seeing whether IT is more vigilant than Finance.
Step 5: Create and launch the campaign
Go to Campaigns → New Campaign:
- Select your Microsoft-themed email template
- Select your M365 user target list
- Select your verified company domain, set sender name (e.g. "IT Security") and sender email (e.g.
[email protected]) - Set a send time or send immediately
- Review and launch
The campaign goes out through PhishSpark's relay, DKIM-signed with your domain's key, from a trusted IP. Recipients see an email from [email protected] that passes all authentication checks in their Microsoft 365 inbox.
Step 6: Read your results
The dashboard updates in real time as events come in: email opened, link clicked, credentials submitted. Employees who click land on a realistic Microsoft sign-in page — because PhishSpark auto-detects the Microsoft branding from your template name. If they enter their email and password, PhishSpark records it as a submission event (the password is redacted — never stored in plaintext) and shows them an immediate training message.
After 48–72 hours, go to Reports to see your overall click rate, department breakdown, awareness score, and risk tier breakdown. Export as CSV for your security report.
How this compares to Microsoft Attack Simulator
| Feature | Microsoft Attack Simulator | PhishSpark |
|---|---|---|
| M365 licence required | E5 or E5 Security add-on ($57/user/mo) | None — works with any M365 plan |
| Setup time | 15–30 min (native integration) | 30 min (domain setup + campaign) |
| Custom sending domain | Yes | Yes (SPF/DKIM/DMARC verified) |
| Department-level reports | Yes | Yes |
| HMAC-secured tracking | No | Yes (prevents false attribution from forwarded emails) |
| Self-hosted option | No | Yes (Docker deployment) |
| Cost for 100 users | $68,400/year (E5 licence uplift) | Free – ₹2,499/mo ($29/mo) |
Start your first M365 phishing simulation
Create a free PhishSpark account — the free tier covers 500 targets and one domain. You can complete the full setup above and launch your first Microsoft 365 phishing test in under 30 minutes, without touching your M365 licensing or upgrading to E5.
Questions about the Defender whitelisting steps for your specific M365 plan? Email [email protected].
Run your first phishing simulation today
Free for up to 500 targets. No credit card, no DevOps, no setup headache.
Get started free