We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Attack simulation training
Attack simulation training, UAE

Microsoft added the UAE to the supported regions, with one feature still missing.

Attack simulation training runs realistic phishing campaigns against your own staff using seven MITRE-derived techniques, predicts how many people a given payload will catch before you send it, and assigns training automatically to whoever falls for it. It is included in Defender for Office 365 Plan 2, which many UAE organisations already own.

Book a phishing simulation reviewSee the techniques
Microsoft attack simulation training for UAE organisations
  • ARE supportedThe UAE is a listed region
  • Seven techniquesSix from MITRE ATT&CK, plus guides
  • QR codesPayloads and training modules for both
  • Already ownedIncluded with Plan 2 and M365 E5
The UAE availability position

The UAE is supported, and one feature is not there yet.

This is worth stating precisely, because it is the question every UAE organisation asks and most vendors answer vaguely.

  • Microsoft lists attack simulation training as available in the APC, EUR and NAM regions, and names ARE, the UAE, among the countries within those regions where it is available. Qatar is also on that list, which matters for organisations operating across both.
  • Microsoft then adds a caveat we are not going to skip over: NOR, ZAF, ARE and DEU are described as the latest additions, and all features except reported email telemetry are available in these regions. Microsoft states it is working to enable the remaining features and will notify customers when reported email telemetry becomes available.
  • In practice that means simulations, payloads, training assignment and the reporting on who clicked and who completed training all work. The gap is in telemetry around messages users report, which affects one part of the reporting picture rather than the ability to run a programme.
  • We verify the current position against your specific tenant before scoping anything, because this is exactly the kind of detail that changes between Microsoft documentation updates, and we would rather check than repeat something that has moved.
What it does

Eight capabilities, starting with the one that decides the whole campaign.

Microsoft frames the design problem honestly: if the phishing message is too close to perfect almost everyone is fooled, and if it is too suspicious nobody is. Most internally run simulations fail on exactly that calibration, and the product has a mechanism for it.

Predicted compromise rate, before you send anything

Microsoft describes predicted compromise rate as using intelligent historical data across Microsoft 365 to predict the percentage of people a payload will compromise, drawing on payload content, aggregated and anonymised compromise rates from other simulations, and payload metadata. You then compare predicted against actual click-through. That turns a simulation from a stunt into a measurement with a baseline.

Seven techniques, six of them from MITRE ATT&CK

Credential harvest, malware attachment, link in attachment, link to malware, drive-by URL and OAuth consent grant, all curated from the MITRE ATT&CK framework, plus the how-to guide which teaches rather than tests. The OAuth consent grant technique is the one most organisations have never simulated and the one that maps to a real and rising attack pattern.

QR code payloads, which matter more here than most places

For several of the techniques the link can be a URL or a QR code, and there are built-in QR code payloads plus training modules covering both malicious digital QR codes and malicious printed QR codes. In a market where QR codes appear on restaurant tables, parking meters, event passes and payment terminals, staff are conditioned to scan without thinking, and this is one of the few tools that tests that reflex directly.

Payload harvesting from your own real phishing

Payload automations, also described as payload harvesting, capture harmless versions of real phishing messages that were actually detected in your Microsoft 365 tenant and reuse them in simulations. That is a materially better test than a generic template, because it reflects what is genuinely being aimed at your organisation rather than what a vendor thought was plausible.

Training assigned by behaviour, not by calendar

Training is assigned based on what a user did or did not do with the simulated message, covering both correct and incorrect actions. Somebody who reported it correctly does not need the same intervention as somebody who entered credentials. That targeting is what makes the training worth people time, and it is the opposite of the annual module everybody clicks through.

Training campaigns and guides, with no test at all

You can assign training directly without putting anybody through a simulation, which suits monthly awareness cycles. How-to guides are a lightweight learning experience users read in their inbox, with built-in guides covering how to report phishing messages and how to recognise and report QR phishing. Not every intervention needs to be a trap, and starting with a guide builds goodwill.

Department by department comparison

Microsoft suggests creating identical simulations, or simulation automations, scoped by department and comparing the results through the reports and insights. That turns a single organisation-wide number into something actionable, because finance clicking at three times the rate of engineering is a specific problem with a specific answer, and the aggregate figure hides it.

Roles that do not require Global Administrator

There are dedicated roles: Attack Simulation Administrator to create and manage campaigns, and Attack Payload Author to build payloads for an administrator to launch later, alongside read-only roles for viewing. Microsoft advocates least privilege explicitly and advises limiting Global Administrator to emergency scenarios, so the person running your phishing programme does not need to be a tenant administrator.

How we approach it

Four things that separate a programme from an embarrassment.

Phishing simulation is the easiest security exercise to run badly, and a badly run one teaches your staff that reporting things to IT gets them humiliated.

We calibrate with predicted compromise rate before sending

Microsoft is explicit that a payload can be too easy or too hard, and predicted compromise rate exists to solve exactly that. We pick payloads with a predicted rate that will produce a usable signal, then compare predicted against actual, which is what makes the result a measurement rather than an anecdote about one clever email.

We agree the culture position before the first campaign

Whether individual results reach managers, whether executives are included, and how results are communicated. Get this wrong and the lasting lesson staff take is that IT sets traps, which suppresses genuine reporting and makes you less safe than before you started. Get it right and reporting rates rise, which is the outcome that actually matters.

We use your real phishing, not stock templates

Payload harvesting turns messages that genuinely reached your tenant into harmless simulations. That reflects what is actually being aimed at your organisation, at your sector, in this market, and it produces both a more honest result and a more useful conversation when somebody asks why they were caught.

We measure by department and act on the difference

Microsoft suggests identical simulations scoped by department and comparing results, and that is the number worth having. An organisation-wide click rate is a headline. Knowing that one team clicks at four times the rate of another is a plan, and it usually points at a workload or process problem rather than a training gap.

Where this matters most

Six UAE situations where a simulation programme earns its place.

The common factor is either a population that receives a lot of external email, or a requirement from somebody outside the business to demonstrate that awareness is tested rather than asserted.

A regulated firm expected to evidence awareness testing

Banks, finance companies, insurers and DIFC or ADGM entities are asked how staff awareness is tested, not whether training was delivered. Simulation results with click rates, reporting rates and trend over time answer that with data. A completion certificate for an annual module does not, and increasingly does not satisfy the question.

Any organisation where finance approves payments

Business email compromise targets a small number of people with authority to move money, and generic training does not reach them with the specificity they need. Scoping a simulation to that population, with a payload that reflects the invoice and payment redirection patterns actually used against UAE firms, tests the control that matters most.

Retail, hospitality and anywhere QR codes are normal

Staff and customers scan codes constantly here, which builds a reflex attackers exploit. The QR code payloads and the two training modules covering malicious digital and malicious printed QR codes address a behaviour that traditional phishing training does not touch at all.

An organisation that has already had an incident

After a real compromise the question from the board is whether it would happen again, and a simulation programme answers it with a number that improves over time. Payload harvesting is particularly apt here, because the message that actually worked can be turned into the test everybody else takes.

A large workforce with limited computer experience

Construction, logistics, manufacturing and facilities management employ many people for whom email is not a native environment. Starting with how-to guides, which teach in the inbox without testing anybody, then moving to simulations, produces better results than opening with a trap that a large proportion of the workforce will fail.

An organisation that already pays for Plan 2 and never used this

The most common situation we find. Attack simulation training is included with Microsoft 365 E5 and Defender for Office 365 Plan 2, and organisations that hold either frequently also pay a separate vendor for phishing simulation. Establishing what you already own is a five minute exercise with an occasionally surprising outcome.

Three positions

How organisations actually test whether staff would fall for phishing.

The middle column, an annual e-learning module with a completion certificate, is the most common in the UAE and measures attendance rather than behaviour.
You know your actual click rate
Simulation programmeYes
Annual training moduleNo
NothingNo
You know which departments are weakest
Simulation programmeYes
Annual training moduleNo
NothingNo
Training targets people who need it
Simulation programmeYes
Annual training moduleNo
NothingNo
QR code behaviour tested
Simulation programmeYes
Annual training moduleNo
NothingNo
OAuth consent behaviour tested
Simulation programmeYes
Annual training moduleNo
NothingNo
Payloads reflect your real threats
Simulation programmeYes
Annual training moduleNo
NothingNo
Difficulty calibrated before sending
Simulation programmeYes
Annual training moduleNot applicable
NothingNot applicable
Improvement measurable over time
Simulation programmeYes
Annual training moduleNo
NothingNo
Evidence for an auditor or insurer
Simulation programmeStrong
Annual training moduleWeak
NothingNone
Frequency in the UAE market
Simulation programmeUncommon
Annual training moduleCommon
NothingCommon in SMEs
Feature
Simulation programme
Annual training module
Nothing
You know your actual click rate
YesNoNo
You know which departments are weakest
YesNoNo
Training targets people who need it
YesNoNo
QR code behaviour tested
YesNoNo
OAuth consent behaviour tested
YesNoNo
Payloads reflect your real threats
YesNoNo
Difficulty calibrated before sending
YesNot applicableNot applicable
Improvement measurable over time
YesNoNo
Evidence for an auditor or insurer
StrongWeakNone
Frequency in the UAE market
UncommonCommonCommon in SMEs
The seven techniques

What each technique simulates, and who it is worth running against.

Six are curated from the MITRE ATT&CK framework. The seventh teaches rather than tests. Most organisations run credential harvest and never try the others, which is a missed opportunity.
TechniqueWhat it simulates
Credential harvestA link to a page themed as a familiar site, asking for username and password
Malware attachmentAn attachment that runs code, such as a macro, when opened
Link in attachmentA hybrid, where the credential harvest link sits inside an attachment
Link to malwareA link to a file on a known sharing site such as SharePoint or Dropbox
Drive-by URLA compromised or cloned familiar site running background code, a watering hole attack
OAuth consent grantA malicious application requesting consent to access data such as the inbox
How-to guideA teaching guide rather than a test, for example how to report phishing
QR code variantsSeveral of the above can deliver the link as a QR code instead of a URL
How a programme runs

Five steps, and the first campaign is not the most important one.

Typically two to three weeks to a first campaign, then a continuing rhythm. The value is in the trend, so the programme design matters more than any single simulation.
  1. 1

    Confirm entitlement and regional availability

    Whether you hold Microsoft 365 E5 or Defender for Office 365 Plan 2, or whether the 90 day Plan 2 trial is the right route, and confirming the current regional position for your tenant including which features are fully enabled. We check rather than assume, because this detail moves.

  2. 2

    Agree the culture position with leadership

    Whether individual results reach managers, whether executives are in scope, how results are communicated and what happens to somebody who clicks. This conversation takes an hour and it determines whether the programme raises reporting rates or suppresses them.

  3. 3

    Design the first campaign and calibrate it

    Technique, payload and population, with predicted compromise rate used to pick something that will produce a usable signal rather than a flattering or a devastating number. Roles assigned properly, using Attack Simulation Administrator rather than a tenant administrator account.

  4. 4

    Run, assign training and read the departmental split

    Training assigned by behaviour rather than to everybody, and results compared by department using identical simulations so the differences mean something. That split is usually where the actionable finding is, and it frequently points at process rather than awareness.

  5. 5

    Establish the rhythm and start harvesting

    Simulation automations for scheduling, payload harvesting so future simulations use real phishing that reached your tenant, and a widening set of techniques over time including OAuth consent grant and QR codes. Then track reporting rate, not just click rate, because reporting is the behaviour you actually want.

Straight answers

What organisations ask about attack simulation training.

Yes, with one documented gap. Microsoft lists availability in the APC, EUR and NAM regions and names ARE, the UAE, among the countries where it is available, alongside Qatar and others. Microsoft also states that ARE is among the latest additions and that all features except reported email telemetry are available in these regions, with work ongoing to enable the remainder. So simulations, payloads, training assignment and click reporting work, and the gap is in telemetry around user-reported messages.

Microsoft states it requires a Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2 licence. There is a subset available to E3 customers as a trial, which Microsoft describes as containing a credential harvest payload and the ability to select ISA phishing or mass market phishing training experiences, with no other capabilities included. There is also a 90 day Defender for Office 365 Plan 2 trial that covers the full feature set.

Our awareness programme is vendor-neutral and covers the whole picture, including policy, process, in-person sessions and content for people who do not work at a desk. This is the Microsoft product inside Defender for Office 365 Plan 2, and it is very good at the specific job of simulating phishing and assigning training based on behaviour. Where an organisation already holds Plan 2, using it as the simulation engine inside a wider programme is usually the sensible answer.

Microsoft frames the problem directly: a phishing message that is too close to perfect fools almost everyone, and one that is too suspicious fools nobody. Predicted compromise rate uses historical data across Microsoft 365, including payload content, payload metadata and aggregated anonymised compromise rates from other simulations, to predict what percentage of people a payload will catch. You then compare predicted against actual, which is how a simulation becomes a measurement.

Yes, and in this market it deserves attention. For several techniques the link can be delivered as a QR code rather than a URL, there are built-in QR code payloads, and there are two training modules covering malicious digital QR codes and malicious printed QR codes, plus a how-to guide on recognising and reporting QR phishing. Staff here scan codes constantly in daily life, which is precisely the reflex an attacker relies on.

Yes, through payload automations, also known as payload harvesting. Microsoft describes it as capturing harmless versions of real-world phishing messages that were detected in Microsoft 365 and using them in simulated campaigns. This is a materially better test than a generic template, because it reflects what is genuinely being sent to your organisation and your sector rather than a plausible invention.

Training is assigned based on the action taken, covering both correct and incorrect actions, so the person who reported the message and the person who entered credentials receive different interventions. What happens beyond that is your decision and should be made before the first campaign, not after it. Our recommendation is consistently that this is measurement rather than discipline, because the alternative suppresses reporting.

Announce that a programme exists, do not announce individual campaigns. Telling people simulations happen sets the expectation that scrutiny is normal and reporting is welcome. Telling them which Tuesday the email arrives measures nothing. The How-to guide technique is useful here, because it lets you teach people how to report before you test whether they will.

Credential harvest, because it is the most common real attack and produces a baseline everybody understands. After that we would push you towards OAuth consent grant, which almost nobody simulates and which maps to a genuine and growing attack pattern where a malicious application asks for access to a mailbox. Link in attachment is also worth running, because attachments carry an assumption of safety that a bare link does not.

Microsoft suggests exactly that: create identical simulations, or simulation automations, scoped by department and compare the results using the reports and insights. In our experience this is where the actionable finding is. An organisation-wide click rate tells you very little, while one team clicking at several times the rate of another is a specific problem, and it often turns out to be about workload or process rather than awareness.

No, and you should not be. There are dedicated roles: Attack Simulation Administrator to create and manage campaigns, and Attack Payload Author to build payloads for somebody else to launch, with read-only roles for viewing results. Microsoft advocates least privilege explicitly and advises limiting Global Administrator to emergency scenarios, so the person running your phishing programme should hold the specific role.

A few, and they are worth knowing before you plan around them. There are no PowerShell cmdlets for attack simulation training, so automation happens inside the product rather than through scripting. On-premises mailboxes are supported but with reduced reporting. Defender XDR unified role-based access control is not currently supported. And simulated phishing URLs can be blocked by Google Safe Browsing, so browser availability is worth checking before a campaign rather than during it.

Frequently enough that scrutiny becomes normal and rare enough that it does not become background noise, which for most organisations lands at monthly or six weekly with varying techniques. Simulation automations support scheduling beyond a simple start and end date, so the rhythm can run without somebody remembering. The number to track over time is the reporting rate, not just the click rate.

Yes. Training campaigns assign training directly to a target population with no simulation involved, which suits a monthly awareness cycle. Separately, the how-to guide technique is a lightweight learning experience users read in their inbox, with built-in guides on reporting phishing and on recognising and reporting QR phishing. Not every intervention needs to be a test, and opening with a guide builds the goodwill the programme depends on.

We scope per organisation, driven by whether you want the programme designed and handed over or run on an ongoing basis with reporting to your board. What we will tell you free in the first conversation is whether your existing licensing already includes it, which for organisations on Microsoft 365 E5 or Defender for Office 365 Plan 2 it does, and whether you are currently paying a separate vendor for something you already own.
Before your first campaign

Fifteen questions worth answering first.

The first group is entitlement and availability. The second is programme design, which is where internally run simulations usually go wrong. The third is the culture question, which decides whether people report phishing to you or hide it.

Entitlement and availability

  • Do you have Defender for Office 365 Plan 2 or M365 E5?
    Those are the stated licence requirements.
  • If you are on E3, do you know what the trial includes?
    A credential harvest payload and two training experiences only.
  • Have you considered the 90 day Plan 2 trial?
    It exists and covers the full capability.
  • Is your tenant region on the supported list?
    ARE is listed, with reported email telemetry pending.
  • Do you have on-premises mailboxes?
    Supported, with reduced reporting functionality.

Programme design

  • What is the predicted compromise rate of your chosen payload?
    Calibrate before sending, not after.
  • Will you scope simulations by department?
    Microsoft suggests identical simulations per department to compare.
  • Have you tried anything beyond credential harvest?
    OAuth consent grant is the underused one.
  • Are QR code payloads in scope?
    Highly relevant to how people behave in this market.
  • Will you harvest payloads from your own real phishing?
    A better test than any generic template.

Culture

  • Has leadership agreed this is measurement, not a trap?
    The framing decides the outcome.
  • Will individual results be shared with managers?
    Decide before the first campaign, and be consistent.
  • Are executives included in the population?
    Excluding them undermines the exercise.
  • Is there an easy way for staff to report suspicious email?
    Reporting is the behaviour you are trying to build.
  • Who runs the programme, and with which role?
    Attack Simulation Administrator, not Global Administrator.
Related reading

The pages around this one.

Security awareness training

The vendor-neutral programme this fits inside, covering policy, in-person sessions and staff who do not work at a desk.

Learn more

Defender for Office 365

The product this feature belongs to, including the plan comparison and the ten second way to tell which one you have.

Learn more

DMARC audit

The technical half of the same problem: stopping people impersonating your domain in the first place.

Learn more
Next step

Check whether you already own this before buying it again.

If you hold Microsoft 365 E5 or Defender for Office 365 Plan 2, attack simulation training is included, and a surprising number of UAE organisations pay a separate vendor for the same capability. That check takes five minutes and we will do it in the first conversation.

Book a phishing simulation reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Security Awareness Training

Phishing simulation and behavior-change training

Learn more

Defender for Office 365

Plan 1 versus Plan 2, and the ten second way to tell which you have

Learn more

DMARC Audit UAE

Stop exact-domain spoofing, and keep your mail delivering

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more

Cybersecurity Companies Dubai

Cyber buyer's guide, 7 services to evaluate

Learn more

Defender for Endpoint

Business, Plan 1 or Plan 2, and what each actually gives you

Learn more

Entra Conditional Access

The control that decides who reaches your data

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy