How to Restrict the Microsoft Defender Menu During Phishing Training
Question details
Users need to restrict or hide navigation options such as Threat Intelligence, Exposure Management, and Settings in the Microsoft Defender portal during attack simulation training.
- Product
- Microsoft Defender
- Device & OS
- not provided
- Scenario
- Conducting phishing and attack simulation training for users within an organization.
- Observed behavior
- Users can still see and access unnecessary navigation menus in the Defender portal during their simulation training.
Ensure you have the necessary global administrator or security administrator privileges in your Microsoft 365 tenant before modifying security policies and role-based access controls.
Consult the Microsoft Defender for Cloud Support Community
Because restricting specific Defender menus during simulations involves complex role-based access control (RBAC) configurations, Microsoft recommends consulting their specialized Defender team.
This specific issue pertains directly to Microsoft Defender portal restrictions rather than standard Exchange Online settings. The Microsoft Defender for Cloud support community is best equipped to provide the exact policy scripts or RBAC configurations required.
Open your web browser and go to the official Microsoft Q&A platform.
Visit the specialized support section using the official tag: https://learn.microsoft.com/en-us/answers/tags/392/defender-for-cloud.
Log in with your administrator account and post your specific requirements about restricting menus during attack simulation training to receive specialized guidance from Microsoft experts.
Configure Role-Based Access Control (RBAC)
You can limit user visibility in the Microsoft 365 Defender portal by assigning custom roles with restricted permissions.
Looking for a Secure and Free Office Suite?
While managing security policies and role-based access in Microsoft Defender can be highly complex, your daily document work doesn't have to be. WPS Office is a lightweight, secure, and free alternative to Microsoft Office that offers seamless format compatibility and an easy-to-use interface without complicated administration settings.

Frequently Asked Questions
Can I completely hide the Threat Intelligence menu for standard users?
Yes, by configuring Role-Based Access Control (RBAC) in the Microsoft 365 Defender portal, administrators can restrict access to specific menus like Threat Intelligence for users who do not require it.
What is Microsoft Defender Attack Simulation Training?
It is a feature in Microsoft Defender for Office 365 that allows organizations to run realistic attack scenarios, such as phishing simulations, to train employees and identify potential vulnerabilities in user behavior.
Why do users see the Settings menu during simulation training?
Users may see the Settings and other administrative menus if their assigned roles in Microsoft Entra ID (formerly Azure AD) or the Microsoft 365 admin center inadvertently grant them broader permissions than what is strictly necessary for standard training modules.




