Breacher.ai Add-On for Microsoft Attack Simulation Training
Your attackers do not stop at email. Your simulation program should not either.
Attack simulation training in Microsoft Defender for Office 365, still widely called Microsoft Attack Simulator, covers the email surface well. Breacher.ai adds the surfaces it was never built for: deepfake video calls, AI voice phishing, SMS and QR, sequenced into a single orchestrated campaign. Campaign and result data moves both ways through the Microsoft Graph attack simulation API, so email and every other channel land on one score instead of two disconnected dashboards.
Free 90-day pilot. Beta cohort holds a discounted rate for the twelve months after.
Configuring a live Microsoft Attack Simulator campaign from inside the platform. Four minutes, unedited.
The deepfake gap in Microsoft Attack Simulation Training
This is not a knock on Microsoft. Attack simulation training does what it was scoped to do. The scope is the problem.
The delivery surface is email
Microsoft's own simulation schema exposes three delivery platforms: email, SMS and Teams. There is no voice call, no video call, and no synthetic media of any kind. The attacks your board is asking about live entirely outside that list.
Stages cannot be chained
Real social engineering arrives in sequence. A text that primes, a call that pressures, a video call that confirms the face. A tool that fires one email in isolation cannot reproduce the thing it is meant to be testing.
Training is catalogue-driven, not finding-driven
Assignment is from a fixed library, matched to a lure type. It cannot build a module around the specific pretext that worked on your finance team last Tuesday, because that module does not exist yet.
Six capabilities on top of what you already run
Nothing here replaces a Microsoft feature. Each one covers ground the native tool does not.
A conversational avatar on a live video call, holding a pretext and responding to challenge. The scenario your finance controls were never tested against, run under authorization against your own people.
Cloned or synthetic voice against the help desk, the finance team, and the people who approve exceptions by phone. Covers both the automated path and the human judgment behind it.
Stages that build on each other across channels and days, with branching on what the target did at the previous step. Your Microsoft email stage can sit inside the sequence rather than beside it.
Build micro modules yourself from live threat intel or from what a simulation just exposed, in minutes, not off a catalogue shelf. Your team writes the prompt, the platform builds the module, you assign it.
Simulations created and scheduled in your tenant outbound. Simulation records, per-user outcomes, user coverage and training coverage read back inbound. Standard Microsoft Graph endpoints, scoped app registration.
Every channel resolves to one two-axis score: DEPTH, how far the worst single case progressed, and SPREAD, weighted population incidence. One number for the board, with the evidence underneath it.
Connect once, then run everything from one plan
The add-on is the Microsoft-connected mode of OSES™, our orchestrated social engineering simulation framework. Same three stages, Simulate, Measure, and Prove it changed, with your Microsoft tenant carrying the email leg.
Before and after the add-on
Everything on the left keeps working. The right is what gets added on top of it.
Free to start, discounted to stay
The connector is in beta. We are being deliberate about how many tenants we onboard while it is, because each one gets direct engineering time.
Generate training modules from live threat intel
The part of your awareness program that ages fastest is the content. This is the part you stop waiting on a vendor for.
Microsoft assigns training from a fixed catalogue, matched to the lure type someone fell for. Every other vendor in the category does a version of the same thing. The module was written before the campaign existed, which means it can describe a category of attack but never the one that actually worked on your people.
Breacher.ai gives your team a generator instead of a library. Point it at a live threat intel report, at the real phishing Microsoft harvested from your own tenant, or at the finding from the simulation that ran last week, and it builds a micro module on that specific pretext. Your team writes the prompt, the platform builds the module, you assign it. No content request, no vendor queue, no waiting for the next catalogue refresh.
Modules carry through to the same place everything else does: completion reported next to your Microsoft training coverage, and the behaviour change measured on the same OSES™ Risk Score as the simulation that triggered it.
Content written months ahead of the threat, refreshed on the vendor's schedule, selected by lure category. A request to cover something new goes into a roadmap you do not control.
Content built from this week's intelligence by the team that read it, on the pretext your own people fell for, in the language of your own process. Refreshed whenever you decide it needs to be.
The channels, explained
Each capability the add-on brings to your Microsoft program has a page of its own covering how it runs and what it proves.
The full orchestrated deepfake simulation service, run standalone rather than as a Microsoft add-on. Video, voice and multi-channel scenarios end to end.
Read moreVoice phishing against the help desk, finance and anyone who approves exceptions by phone. The channel Microsoft's delivery model has no entry for.
Read moreExecutive impersonation against your payment approval chain, using the cloned voice and likeness an attacker would build from public material.
Read moreMulti-participant video call impersonation, the scenario behind the largest published deepfake fraud losses. Nothing in a mail filter touches it.
Read moreThe two-axis model every channel resolves to. DEPTH, SPREAD, four bands, and how the score is calibrated across a population.
Read moreWhere the AI training modules live: micro content triggered by a finding, distinct from a standing annual curriculum on a renewal cycle.
Read moreWhat you need before the scoping call
Short list. We confirm all of it with you rather than assuming any of it.
Common questions
What is Microsoft Attack Simulation Training?
It is the phishing simulation capability built into Microsoft Defender for Office 365, reached from the Defender portal under Email and collaboration. It sends benign phishing payloads to your own users, tracks who clicked, opened the payload or entered credentials, and assigns training from a built-in catalogue to the people who engaged. It requires Microsoft 365 E5 or Defender for Office 365 Plan 2.
What is the difference between Attack Simulator and Attack simulation training?
They are the same capability under two names. Attack Simulator was the original Office 365 name and was retired around 2020 when the feature moved into Microsoft Defender for Office 365 and was rebuilt as Attack simulation training. Microsoft documentation now uses Attack simulation training exclusively, but the old name is still in wide use, and the portal URL still contains the word attacksimulator.
Does Microsoft Attack Simulation Training support deepfake or voice phishing simulations?
No. Microsoft's own simulation model exposes three delivery platforms: email, SMS and Teams. There is no voice call, no video call and no synthetic media of any kind anywhere in it. Payloads are links, attachments and QR codes inside email. Deepfake video impersonation and AI voice phishing sit entirely outside what the native tool can deliver, which is the specific gap this add-on fills.
Is there an API for Microsoft Attack Simulation Training?
Yes. The Microsoft Graph attack simulation API covers it. On the read side you can list simulations, get a single simulation, pull the report overview and per-user detail, and retrieve tenant-level user coverage and training coverage. On the write side you can create, update and delete simulations. That is what makes a genuine two-way integration possible rather than a report export.
Can Attack simulation training send SMS or Microsoft Teams messages?
SMS and Teams both appear as delivery platforms in Microsoft's simulation model, so the capability exists alongside email. Availability varies by tenant and environment, and some advanced features including payload automation and recommended payloads are not offered in GCC High and DoD. What none of those channels give you is a live voice or video interaction, which is a different kind of test rather than a different message format.
Do we have to replace Microsoft Attack simulation training?
No. That is the point of the add-on. Your Microsoft tenant stays the system of record for email simulations, your existing payloads and campaigns keep running untouched, and nothing is migrated. Breacher.ai adds the channels Attack simulation training does not deliver and brings both sets of results into one view.
What does bi-directional sync actually do?
It uses the Microsoft Graph attack simulation API. Outbound, Breacher.ai can create and schedule simulations in your Microsoft tenant so an email stage sits inside a wider campaign. Inbound, it reads simulation records, per-user outcome detail, user coverage and training coverage back out of Microsoft. Those results are then scored alongside the voice, video, SMS and QR stages that ran outside Microsoft.
Can you write AI training modules into Microsoft's training library?
No, and any vendor telling you otherwise is overselling. Microsoft's training catalogue is delivered through its own content partnership and is not open to third-party content. Breacher.ai builds and hosts AI-generated micro training modules on the OSES™ Behave side, triggered by what a specific simulation exposed, and reports completion next to your Microsoft training coverage rather than inside it.
What licensing do we need?
Attack simulation training itself requires Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2, and the Graph attack simulation endpoints follow the same entitlement. If you are on E3 you can still run the Breacher.ai channels, you simply will not have a Microsoft side to sync with. We confirm licensing on the scoping call before anything is connected.
What permissions does the connection need?
An Entra ID application registration scoped to the attack simulation endpoints, consented by a Global Administrator or Security Administrator. Read-only is enough if you only want unified reporting. Read and write is needed if you want Breacher.ai to schedule the Microsoft email stage as part of an orchestrated campaign. We will run the narrower of the two unless you ask otherwise.
How is consent handled for voice and video impersonation?
Consent is enforced by the product, not by a form. Before the platform will generate a voice or likeness, the individual being cloned completes a biometric and voice verification of their own consent, and that obligation is carried in the service agreement as well. An administrator cannot authorize the cloning of somebody else, which means no executive voice or likeness is ever produced on the strength of a security team's approval alone. Recorded-call scenarios are separately configured to the recording consent law of every jurisdiction your targets sit in.
Can we build our own training modules from threat intelligence?
Yes, and this is the part most teams tell us they want first. Your team points the generator at a source, a live threat advisory, the real phishing Microsoft harvested from your tenant, a finding from last week's simulation, or your own payment approval policy, and the platform builds a micro module on that specific pretext. You write the prompt, you review the output, you assign it. There is no content request queue and no waiting for a vendor catalogue refresh.
Who runs the simulations, your team or ours?
Yours. This is a platform you operate under a service agreement, not a managed engagement we deliver. Your team designs the campaign, selects the channels, generates the training and reads the results. That is a deliberate difference from our red team services, which are separately scoped and separately priced if you want us running it instead.
What does the beta cost, and what is the catch?
The 90-day pilot is free and open while seats last. When it ends, accepted beta cohort members hold a discounted rate for the following twelve months rather than moving to list price, and that rate is locked for the full term. In exchange we ask for structured feedback on the connector and the reporting model, and the option to reference the engagement pattern in anonymized form. We never name a client in public material. Seats are limited because each beta tenant gets direct engineering support during the connector build.
How long does it take to stand up?
The connection itself is an application registration and a consent grant, usually under an hour once approvals are in hand. The first orchestrated campaign typically runs one to two weeks after the scoping call, with scenario design and consent collection accounting for most of that window.
Apply for the beta
Thirty minutes. We will look at what your Microsoft program covers today and design the first orchestrated campaign around what it does not.
Or read how we score it on the OSES™ Risk Score page.
Breacher.ai Corp. is an independent vendor and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation. Microsoft, Microsoft 365, Microsoft Defender for Office 365, Microsoft Graph, Entra ID and Teams are trademarks of Microsoft Corporation, referenced here only to describe interoperability. Product capabilities described on this page reflect Microsoft documentation current at the time of writing and are subject to change by Microsoft. Customers operate the platform under a service agreement, against their own tenant and their own personnel. Cloning of any individual's voice or likeness is gated by in-product biometric and voice verification of that individual and is contractually restricted under the same agreement. Channel partners and MSSPs, see partners.
