Microsoft Attack Simulator Alternatives: Keep Defender, Add Voice, SMS and Callback
Microsoft Attack Simulator only sends email. Keep Defender and the native report button, and add voice, SMS, QR and callback simulation with Keepnet.
Ozan Ucar, Founder and CEO of Keepnet
Almost every organization that asks about Microsoft Attack Simulator alternatives already owns it. The question is rarely whether to drop it. It is what to do about the attacks it cannot send.
One scoping note first. Microsoft Defender for Office 365 is a large security product and Keepnet is not an alternative to most of it. Threat protection, safe links, safe attachments and the rest of the suite sit outside what Keepnet does. This comparison covers one feature inside it: Attack simulation training, the phishing simulation and awareness module.
What Does Microsoft Attack Simulator Do Well?
It is already there, and that matters. If you hold Microsoft 365 E5 or Defender for Office 365 Plan 2, Attack simulation training is included at no extra licence cost, it needs no mail flow changes, and the simulated messages are not fighting your own gateway.
The payload catalog is the second strength. Microsoft builds its templates from attacks observed in its own data centres and adds roughly 30 to 40 new payloads a month, and each payload carries a predicted compromise rate drawn from Microsoft 365 wide data. Few vendors can offer a benchmark of that size.
Reporting is native. Results land in the Defender portal next to the rest of your security telemetry, which is convenient for a team that already lives there.
Why Teams Look for a Microsoft Attack Simulator Alternative
Three reasons come up most often, and the first one is a hard limit rather than a preference.
The payload is an email. Always. Microsoft documentation is explicit: when you create a payload, the type you select is Email. Seven social engineering techniques are available, credential harvest, malware attachment, link in attachment, link to malware, drive-by URL, OAuth consent grant and how-to guide, and every one of them is delivered to the inbox.
QR codes are supported, and the detail matters. A QR code replaces the phishing link inside the simulation email. That is a QR lure in an email, not a separate channel with its own reporting. A text message sent to a phone, a call placed to a number, a callback number the employee dials, an MFA prompt they approve or a synthetic voice in a meeting: none of these can be simulated.
That gap sits exactly where people fail most. In the 2026 Verizon Data Breach Investigations Report, the median click rate is about 1.4 percent on email simulations and about 2 percent on phone-centric ones (Verizon, 2026 Data Breach Investigations Report, 2026, p. 50).
It is gated behind the top licence. Attack simulation training requires Microsoft 365 E5 or Defender for Office 365 Plan 2. Organizations on Business Premium or Plan 1 do not have it, and buying up to E5 for a phishing simulation is rarely the cheapest way to get one.
The training layer is thin next to the simulation layer. The simulation engine is strong. What follows the click, the course library, role based paths, localization beyond translation and delivery into an LMS you already own, is where most teams end up buying something else.
How Keepnet Is Different
Keepnet runs simulations on six channels from one platform: email, voice, SMS, QR, callback and deepfake. Each channel reports separately, so the phone result is never hidden inside an email average.
Voice simulations place an actual call to the employee own phone, from one of your local numbers, with a two way AI conversation rather than a recording. See vishing simulation.
SMS and QR reach the device itself and are measured on their own. See smishing simulation and quishing simulation.
Callback phishing is its own channel: the employee dials the number and speaks to an agent, and what happens after the dial is measured. See callback phishing simulation.
You do not have to give up the Microsoft workflow to get any of this. Employees keep using the native Microsoft report button, and the report is routed to both Microsoft Defender and Keepnet Incident Responder. Nobody learns a new habit. See how the reporter button works.
Reports can also come from the phone. Keepnet Reporter gives employees a way to report a suspicious text message or call, which is the one path Attack simulation training has no answer for.
Licensing works differently as well. Every product can be bought on its own and the full platform is optional, so adding the voice channel does not require moving your Microsoft licence tier. Training is SCORM compatible and runs inside the LMS you already use.
Keepnet vs Microsoft Attack Simulator: What to Compare
| Dimension | Keepnet | What to check on any alternative |
|---|---|---|
| Payload type | Email, voice, SMS, QR, callback, MFA fatigue and deepfake, each reported separately | Microsoft documentation lists one payload type, Email, across seven techniques. Ask which channels can actually be sent |
| QR simulation | Its own channel, sent and measured on its own | A QR code placed inside a simulation email is an email lure. Ask where the QR result is reported |
| Voice simulation | A real call to the employee own phone from one of your local numbers, two way AI conversation | Can the platform place a call at all |
| Callback phishing | Its own channel: the employee dials and speaks to an agent | Is anything measured after the employee dials |
| Mobile reporting | A report button on the phone for SMS and calls | Where does an employee report a text message or a call |
| Microsoft workflow | Native Microsoft report button kept, reports routed to both Defender and Keepnet Incident Responder | Does adding a platform force a new reporting habit |
| Licence requirement | Bought on its own, independent of your Microsoft tier | Attack simulation training needs Microsoft 365 E5 or Defender for Office 365 Plan 2 |
| Training delivery | SCORM compatible, runs inside your own LMS with tracking intact | Can you keep your existing LMS |
| Buying model | Every product can be bought on its own, the platform is optional | Can you start with one channel |
Keepnet compared with Microsoft Attack simulation training
Can You Run Keepnet Alongside Microsoft?
Yes, and here it is almost always the right answer rather than a compromise. Defender keeps doing email, the native report button stays where it is, and Keepnet adds the channels that cannot be sent from the Defender portal. Nothing is switched off and no licence tier has to move.
Which Microsoft Attack Simulator Alternative Fits Your Reason?
If the reason is the phone, look for a platform that places a real call and sends a real text, and that reports each channel separately.
If the reason is licensing, check whether the simulation product can be bought without upgrading your Microsoft plan.
If the reason is reporting, ask what happens to a suspicious SMS or call, and whether email reports still reach Defender afterwards.
If the reason is training, look past the course count. Ask whether content adapts by role, language and region, and whether it runs in the LMS you already own.
See It on Your Own Environment
The fastest comparison is a short pilot on the channel Defender cannot send. One voice campaign and one SMS campaign on a small group will show you more than any feature table, including this one. Book a demo and we will run it on your own users.
For a wider view, see our comparison of security awareness training platforms, and the Mimecast, Proofpoint and KnowBe4 comparisons.