Microsoft added the UAE to the supported regions, with one feature still missing.
Attack simulation training runs realistic phishing campaigns against your own staff using seven MITRE-derived techniques, predicts how many people a given payload will catch before you send it, and assigns training automatically to whoever falls for it. It is included in Defender for Office 365 Plan 2, which many UAE organisations already own.

- ARE supportedThe UAE is a listed region
- Seven techniquesSix from MITRE ATT&CK, plus guides
- QR codesPayloads and training modules for both
- Already ownedIncluded with Plan 2 and M365 E5
The UAE is supported, and one feature is not there yet.
This is worth stating precisely, because it is the question every UAE organisation asks and most vendors answer vaguely.
- Microsoft lists attack simulation training as available in the APC, EUR and NAM regions, and names ARE, the UAE, among the countries within those regions where it is available. Qatar is also on that list, which matters for organisations operating across both.
- Microsoft then adds a caveat we are not going to skip over: NOR, ZAF, ARE and DEU are described as the latest additions, and all features except reported email telemetry are available in these regions. Microsoft states it is working to enable the remaining features and will notify customers when reported email telemetry becomes available.
- In practice that means simulations, payloads, training assignment and the reporting on who clicked and who completed training all work. The gap is in telemetry around messages users report, which affects one part of the reporting picture rather than the ability to run a programme.
- We verify the current position against your specific tenant before scoping anything, because this is exactly the kind of detail that changes between Microsoft documentation updates, and we would rather check than repeat something that has moved.
Eight capabilities, starting with the one that decides the whole campaign.
Predicted compromise rate, before you send anything
Microsoft describes predicted compromise rate as using intelligent historical data across Microsoft 365 to predict the percentage of people a payload will compromise, drawing on payload content, aggregated and anonymised compromise rates from other simulations, and payload metadata. You then compare predicted against actual click-through. That turns a simulation from a stunt into a measurement with a baseline.
Seven techniques, six of them from MITRE ATT&CK
Credential harvest, malware attachment, link in attachment, link to malware, drive-by URL and OAuth consent grant, all curated from the MITRE ATT&CK framework, plus the how-to guide which teaches rather than tests. The OAuth consent grant technique is the one most organisations have never simulated and the one that maps to a real and rising attack pattern.
QR code payloads, which matter more here than most places
For several of the techniques the link can be a URL or a QR code, and there are built-in QR code payloads plus training modules covering both malicious digital QR codes and malicious printed QR codes. In a market where QR codes appear on restaurant tables, parking meters, event passes and payment terminals, staff are conditioned to scan without thinking, and this is one of the few tools that tests that reflex directly.
Payload harvesting from your own real phishing
Payload automations, also described as payload harvesting, capture harmless versions of real phishing messages that were actually detected in your Microsoft 365 tenant and reuse them in simulations. That is a materially better test than a generic template, because it reflects what is genuinely being aimed at your organisation rather than what a vendor thought was plausible.
Training assigned by behaviour, not by calendar
Training is assigned based on what a user did or did not do with the simulated message, covering both correct and incorrect actions. Somebody who reported it correctly does not need the same intervention as somebody who entered credentials. That targeting is what makes the training worth people time, and it is the opposite of the annual module everybody clicks through.
Training campaigns and guides, with no test at all
You can assign training directly without putting anybody through a simulation, which suits monthly awareness cycles. How-to guides are a lightweight learning experience users read in their inbox, with built-in guides covering how to report phishing messages and how to recognise and report QR phishing. Not every intervention needs to be a trap, and starting with a guide builds goodwill.
Department by department comparison
Microsoft suggests creating identical simulations, or simulation automations, scoped by department and comparing the results through the reports and insights. That turns a single organisation-wide number into something actionable, because finance clicking at three times the rate of engineering is a specific problem with a specific answer, and the aggregate figure hides it.
Roles that do not require Global Administrator
There are dedicated roles: Attack Simulation Administrator to create and manage campaigns, and Attack Payload Author to build payloads for an administrator to launch later, alongside read-only roles for viewing. Microsoft advocates least privilege explicitly and advises limiting Global Administrator to emergency scenarios, so the person running your phishing programme does not need to be a tenant administrator.
Four things that separate a programme from an embarrassment.
We calibrate with predicted compromise rate before sending
Microsoft is explicit that a payload can be too easy or too hard, and predicted compromise rate exists to solve exactly that. We pick payloads with a predicted rate that will produce a usable signal, then compare predicted against actual, which is what makes the result a measurement rather than an anecdote about one clever email.
We agree the culture position before the first campaign
Whether individual results reach managers, whether executives are included, and how results are communicated. Get this wrong and the lasting lesson staff take is that IT sets traps, which suppresses genuine reporting and makes you less safe than before you started. Get it right and reporting rates rise, which is the outcome that actually matters.
We use your real phishing, not stock templates
Payload harvesting turns messages that genuinely reached your tenant into harmless simulations. That reflects what is actually being aimed at your organisation, at your sector, in this market, and it produces both a more honest result and a more useful conversation when somebody asks why they were caught.
We measure by department and act on the difference
Microsoft suggests identical simulations scoped by department and comparing results, and that is the number worth having. An organisation-wide click rate is a headline. Knowing that one team clicks at four times the rate of another is a plan, and it usually points at a workload or process problem rather than a training gap.
Six UAE situations where a simulation programme earns its place.
A regulated firm expected to evidence awareness testing
Banks, finance companies, insurers and DIFC or ADGM entities are asked how staff awareness is tested, not whether training was delivered. Simulation results with click rates, reporting rates and trend over time answer that with data. A completion certificate for an annual module does not, and increasingly does not satisfy the question.
Any organisation where finance approves payments
Business email compromise targets a small number of people with authority to move money, and generic training does not reach them with the specificity they need. Scoping a simulation to that population, with a payload that reflects the invoice and payment redirection patterns actually used against UAE firms, tests the control that matters most.
Retail, hospitality and anywhere QR codes are normal
Staff and customers scan codes constantly here, which builds a reflex attackers exploit. The QR code payloads and the two training modules covering malicious digital and malicious printed QR codes address a behaviour that traditional phishing training does not touch at all.
An organisation that has already had an incident
After a real compromise the question from the board is whether it would happen again, and a simulation programme answers it with a number that improves over time. Payload harvesting is particularly apt here, because the message that actually worked can be turned into the test everybody else takes.
A large workforce with limited computer experience
Construction, logistics, manufacturing and facilities management employ many people for whom email is not a native environment. Starting with how-to guides, which teach in the inbox without testing anybody, then moving to simulations, produces better results than opening with a trap that a large proportion of the workforce will fail.
An organisation that already pays for Plan 2 and never used this
The most common situation we find. Attack simulation training is included with Microsoft 365 E5 and Defender for Office 365 Plan 2, and organisations that hold either frequently also pay a separate vendor for phishing simulation. Establishing what you already own is a five minute exercise with an occasionally surprising outcome.
How organisations actually test whether staff would fall for phishing.
| Feature | Simulation programme | Annual training module | Nothing |
|---|---|---|---|
You know your actual click rate | Yes | No | No |
You know which departments are weakest | Yes | No | No |
Training targets people who need it | Yes | No | No |
QR code behaviour tested | Yes | No | No |
OAuth consent behaviour tested | Yes | No | No |
Payloads reflect your real threats | Yes | No | No |
Difficulty calibrated before sending | Yes | Not applicable | Not applicable |
Improvement measurable over time | Yes | No | No |
Evidence for an auditor or insurer | Strong | Weak | None |
Frequency in the UAE market | Uncommon | Common | Common in SMEs |
What each technique simulates, and who it is worth running against.
| Technique | What it simulates | |
|---|---|---|
| Credential harvest | A link to a page themed as a familiar site, asking for username and password | |
| Malware attachment | An attachment that runs code, such as a macro, when opened | |
| Link in attachment | A hybrid, where the credential harvest link sits inside an attachment | |
| Link to malware | A link to a file on a known sharing site such as SharePoint or Dropbox | |
| Drive-by URL | A compromised or cloned familiar site running background code, a watering hole attack | |
| OAuth consent grant | A malicious application requesting consent to access data such as the inbox | |
| How-to guide | A teaching guide rather than a test, for example how to report phishing | |
| QR code variants | Several of the above can deliver the link as a QR code instead of a URL |
Five steps, and the first campaign is not the most important one.
- 1
Confirm entitlement and regional availability
Whether you hold Microsoft 365 E5 or Defender for Office 365 Plan 2, or whether the 90 day Plan 2 trial is the right route, and confirming the current regional position for your tenant including which features are fully enabled. We check rather than assume, because this detail moves.
- 2
Agree the culture position with leadership
Whether individual results reach managers, whether executives are in scope, how results are communicated and what happens to somebody who clicks. This conversation takes an hour and it determines whether the programme raises reporting rates or suppresses them.
- 3
Design the first campaign and calibrate it
Technique, payload and population, with predicted compromise rate used to pick something that will produce a usable signal rather than a flattering or a devastating number. Roles assigned properly, using Attack Simulation Administrator rather than a tenant administrator account.
- 4
Run, assign training and read the departmental split
Training assigned by behaviour rather than to everybody, and results compared by department using identical simulations so the differences mean something. That split is usually where the actionable finding is, and it frequently points at process rather than awareness.
- 5
Establish the rhythm and start harvesting
Simulation automations for scheduling, payload harvesting so future simulations use real phishing that reached your tenant, and a widening set of techniques over time including OAuth consent grant and QR codes. Then track reporting rate, not just click rate, because reporting is the behaviour you actually want.
What organisations ask about attack simulation training.
Fifteen questions worth answering first.
Entitlement and availability
- Do you have Defender for Office 365 Plan 2 or M365 E5?Those are the stated licence requirements.
- If you are on E3, do you know what the trial includes?A credential harvest payload and two training experiences only.
- Have you considered the 90 day Plan 2 trial?It exists and covers the full capability.
- Is your tenant region on the supported list?ARE is listed, with reported email telemetry pending.
- Do you have on-premises mailboxes?Supported, with reduced reporting functionality.
Programme design
- What is the predicted compromise rate of your chosen payload?Calibrate before sending, not after.
- Will you scope simulations by department?Microsoft suggests identical simulations per department to compare.
- Have you tried anything beyond credential harvest?OAuth consent grant is the underused one.
- Are QR code payloads in scope?Highly relevant to how people behave in this market.
- Will you harvest payloads from your own real phishing?A better test than any generic template.
Culture
- Has leadership agreed this is measurement, not a trap?The framing decides the outcome.
- Will individual results be shared with managers?Decide before the first campaign, and be consistent.
- Are executives included in the population?Excluding them undermines the exercise.
- Is there an easy way for staff to report suspicious email?Reporting is the behaviour you are trying to build.
- Who runs the programme, and with which role?Attack Simulation Administrator, not Global Administrator.
The pages around this one.
Security awareness training
The vendor-neutral programme this fits inside, covering policy, in-person sessions and staff who do not work at a desk.
Defender for Office 365
The product this feature belongs to, including the plan comparison and the ten second way to tell which one you have.
DMARC audit
The technical half of the same problem: stopping people impersonating your domain in the first place.
Check whether you already own this before buying it again.
If you hold Microsoft 365 E5 or Defender for Office 365 Plan 2, attack simulation training is included, and a surprising number of UAE organisations pay a separate vendor for the same capability. That check takes five minutes and we will do it in the first conversation.
Related Services
Explore more solutions that work great with this service
Security Awareness Training
Phishing simulation and behavior-change training
Defender for Office 365
Plan 1 versus Plan 2, and the ten second way to tell which you have
DMARC Audit UAE
Stop exact-domain spoofing, and keep your mail delivering
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
Cybersecurity Companies Dubai
Cyber buyer's guide, 7 services to evaluate
Defender for Endpoint
Business, Plan 1 or Plan 2, and what each actually gives you
Entra Conditional Access
The control that decides who reaches your data