Keepnet – AI-powered human risk management platform logo
Menu
HOME > blog > keepnet microsoft attack simulator alternative

Microsoft Attack Simulator Alternatives: Keep Defender, Add Voice, SMS and Callback

Microsoft Attack Simulator only sends email. Keep Defender and the native report button, and add voice, SMS, QR and callback simulation with Keepnet.

Ozan Ucar, Founder and CEO of Keepnet

Comparison graphic: an organization wide risk score on one side, and per channel susceptibility for email, voice, SMS, QR, callback and deepfake on the other.

Almost every organization that asks about Microsoft Attack Simulator alternatives already owns it. The question is rarely whether to drop it. It is what to do about the attacks it cannot send.

One scoping note first. Microsoft Defender for Office 365 is a large security product and Keepnet is not an alternative to most of it. Threat protection, safe links, safe attachments and the rest of the suite sit outside what Keepnet does. This comparison covers one feature inside it: Attack simulation training, the phishing simulation and awareness module.

What Does Microsoft Attack Simulator Do Well?

It is already there, and that matters. If you hold Microsoft 365 E5 or Defender for Office 365 Plan 2, Attack simulation training is included at no extra licence cost, it needs no mail flow changes, and the simulated messages are not fighting your own gateway.

The payload catalog is the second strength. Microsoft builds its templates from attacks observed in its own data centres and adds roughly 30 to 40 new payloads a month, and each payload carries a predicted compromise rate drawn from Microsoft 365 wide data. Few vendors can offer a benchmark of that size.

Reporting is native. Results land in the Defender portal next to the rest of your security telemetry, which is convenient for a team that already lives there.

Why Teams Look for a Microsoft Attack Simulator Alternative

Three reasons come up most often, and the first one is a hard limit rather than a preference.

The payload is an email. Always. Microsoft documentation is explicit: when you create a payload, the type you select is Email. Seven social engineering techniques are available, credential harvest, malware attachment, link in attachment, link to malware, drive-by URL, OAuth consent grant and how-to guide, and every one of them is delivered to the inbox.

QR codes are supported, and the detail matters. A QR code replaces the phishing link inside the simulation email. That is a QR lure in an email, not a separate channel with its own reporting. A text message sent to a phone, a call placed to a number, a callback number the employee dials, an MFA prompt they approve or a synthetic voice in a meeting: none of these can be simulated.

That gap sits exactly where people fail most. In the 2026 Verizon Data Breach Investigations Report, the median click rate is about 1.4 percent on email simulations and about 2 percent on phone-centric ones (Verizon, 2026 Data Breach Investigations Report, 2026, p. 50).

It is gated behind the top licence. Attack simulation training requires Microsoft 365 E5 or Defender for Office 365 Plan 2. Organizations on Business Premium or Plan 1 do not have it, and buying up to E5 for a phishing simulation is rarely the cheapest way to get one.

The training layer is thin next to the simulation layer. The simulation engine is strong. What follows the click, the course library, role based paths, localization beyond translation and delivery into an LMS you already own, is where most teams end up buying something else.

How Keepnet Is Different

Keepnet runs simulations on six channels from one platform: email, voice, SMS, QR, callback and deepfake. Each channel reports separately, so the phone result is never hidden inside an email average.

Voice simulations place an actual call to the employee own phone, from one of your local numbers, with a two way AI conversation rather than a recording. See vishing simulation.

SMS and QR reach the device itself and are measured on their own. See smishing simulation and quishing simulation.

Callback phishing is its own channel: the employee dials the number and speaks to an agent, and what happens after the dial is measured. See callback phishing simulation.

You do not have to give up the Microsoft workflow to get any of this. Employees keep using the native Microsoft report button, and the report is routed to both Microsoft Defender and Keepnet Incident Responder. Nobody learns a new habit. See how the reporter button works.

Reports can also come from the phone. Keepnet Reporter gives employees a way to report a suspicious text message or call, which is the one path Attack simulation training has no answer for.

Licensing works differently as well. Every product can be bought on its own and the full platform is optional, so adding the voice channel does not require moving your Microsoft licence tier. Training is SCORM compatible and runs inside the LMS you already use.

Susceptibility measured per channel, not as a single organization wide average.

Keepnet vs Microsoft Attack Simulator: What to Compare

DimensionKeepnetWhat to check on any alternative
Payload typeEmail, voice, SMS, QR, callback, MFA fatigue and deepfake, each reported separatelyMicrosoft documentation lists one payload type, Email, across seven techniques. Ask which channels can actually be sent
QR simulationIts own channel, sent and measured on its ownA QR code placed inside a simulation email is an email lure. Ask where the QR result is reported
Voice simulationA real call to the employee own phone from one of your local numbers, two way AI conversationCan the platform place a call at all
Callback phishingIts own channel: the employee dials and speaks to an agentIs anything measured after the employee dials
Mobile reportingA report button on the phone for SMS and callsWhere does an employee report a text message or a call
Microsoft workflowNative Microsoft report button kept, reports routed to both Defender and Keepnet Incident ResponderDoes adding a platform force a new reporting habit
Licence requirementBought on its own, independent of your Microsoft tierAttack simulation training needs Microsoft 365 E5 or Defender for Office 365 Plan 2
Training deliverySCORM compatible, runs inside your own LMS with tracking intactCan you keep your existing LMS
Buying modelEvery product can be bought on its own, the platform is optionalCan you start with one channel

Keepnet compared with Microsoft Attack simulation training

Can You Run Keepnet Alongside Microsoft?

Yes, and here it is almost always the right answer rather than a compromise. Defender keeps doing email, the native report button stays where it is, and Keepnet adds the channels that cannot be sent from the Defender portal. Nothing is switched off and no licence tier has to move.

Which Microsoft Attack Simulator Alternative Fits Your Reason?

If the reason is the phone, look for a platform that places a real call and sends a real text, and that reports each channel separately.

If the reason is licensing, check whether the simulation product can be bought without upgrading your Microsoft plan.

If the reason is reporting, ask what happens to a suspicious SMS or call, and whether email reports still reach Defender afterwards.

If the reason is training, look past the course count. Ask whether content adapts by role, language and region, and whether it runs in the LMS you already own.

See It on Your Own Environment

The fastest comparison is a short pilot on the channel Defender cannot send. One voice campaign and one SMS campaign on a small group will show you more than any feature table, including this one. Book a demo and we will run it on your own users.

For a wider view, see our comparison of security awareness training platforms, and the Mimecast, Proofpoint and KnowBe4 comparisons.

SHARE ON

twitter
linkedin
facebook

Which channel can your Defender simulations not send?

Book a 30 minute Keepnet walkthrough and run it against your own users.
tickKeep Defender and the native report button where they are.
tickAdd voice, callback, SMS and QR simulation from one console.
tickMeasure susceptibility per channel, not as one average.

Frequently Asked Questions

What is Microsoft Attack Simulator?

arrow down

Attack simulation training is the phishing simulation and awareness feature inside Microsoft Defender for Office 365. It sends simulated phishing emails to your users, tracks who is compromised and assigns follow up training.

What licence do you need for Attack simulation training?

arrow down

Microsoft documentation states it is available in Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2. Business Premium and Plan 1 tenants do not have it.

Which techniques does Microsoft Attack Simulator support?

arrow down

Seven: credential harvest, malware attachment, link in attachment, link to malware, drive-by URL, OAuth consent grant and how-to guide. All of them are delivered as email.

Does Microsoft Attack Simulator support QR code phishing?

arrow down

Yes, but inside the email. A QR code can replace the phishing link in the simulation message. It is a lure inside an email rather than a separate channel with its own reporting.

Can Microsoft Attack Simulator send SMS or place phone calls?

arrow down

No. Microsoft documentation gives one payload type, Email. Text message, voice call, callback and deepfake simulations are not available.

Why does the phone channel matter?

arrow down

It is where people fail more often. In the 2026 Verizon Data Breach Investigations Report, the median click rate is about 1.4 percent on email simulations and about 2 percent on phone-centric ones (Verizon, 2026 Data Breach Investigations Report, 2026, p. 50).

Can Keepnet run alongside Microsoft Defender?

arrow down

Yes, and that is the usual setup. Defender keeps email, and Keepnet adds voice, SMS, QR, callback, MFA fatigue and deepfake. No mail flow change and no licence upgrade.

Do employees have to learn a new reporting button?

arrow down

No. The native Microsoft report button stays, and reports are routed to both Microsoft Defender and Keepnet Incident Responder.

How do employees report a suspicious text message or call?

arrow down

Keepnet Reporter puts a report button on the phone itself, and those reports join the same pipeline as email reports.

Do we need to move to Microsoft 365 E5 to use Keepnet?

arrow down

No. Keepnet is licensed on its own and every product can be bought separately, so your Microsoft plan does not have to change.