Microsoft Attack Simulator Unique Payloads and Target Users Explained
Question details
The user needs an explanation of the 'unique payloads' and 'target all selected users' features within Microsoft Attack Simulator automations.

- Product
- Microsoft Attack Simulator
- Device & OS
- not provided
- Scenario
- Configuring automated simulated phishing campaigns for employee security training.
- Observed behavior
- Seeking a clear understanding of payload distribution and user targeting mechanics to configure effective simulation runs.
Ensure you have the appropriate administrative permissions, such as Attack Simulation Administrator or Security Administrator, within the Microsoft 365 Defender portal before configuring simulation automations.
Understanding Attack Simulator Automation Settings
Clarification on how unique payloads and target user settings function during automated Microsoft Attack Simulator runs.
When setting up automated simulation runs in Microsoft 365 Defender, administrators can customize payload delivery and user targeting to create varied and realistic phishing scenarios. Properly configuring these options prevents predictable testing patterns.
Selecting the 'unique payloads' option ensures that every automated run utilizes different simulated content. This means the system will automatically vary the phishing messages, malicious links, or attachments so users do not receive the exact same test multiple times.
Enabling the option to target all selected users means that every single user included in the automation's target list will receive a payload during each scheduled run. For instance, if 100 users are selected, all 100 individuals will be targeted in every single simulation triggered by that specific automation.

Need a Lightweight Alternative to Microsoft Office? Try WPS Office
While Microsoft 365 offers enterprise security tools like Attack Simulator, it can be resource-intensive and costly. If you need a fast, free, and highly compatible office suite for standard document creation and editing, WPS Office is an excellent, lightweight alternative.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install the Software: Run the downloaded executable file and follow the straightforward on-screen instructions to complete the installation.
- 3. Start Creating Documents: Launch WPS Office and instantly begin creating or editing your documents, spreadsheets, and presentations without needing a complex setup.

Frequently Asked Questions
What happens if I don't use unique payloads in my simulation runs?
If unique payloads are disabled, the Attack Simulator may send the same phishing message or simulated attack multiple times. Users might easily recognize the duplicate test, which heavily reduces the educational value of the security training.
Can I modify the target user list after an automation starts?
Yes, administrators can update the target user lists within the Microsoft 365 Defender portal. However, these updates will only apply to future simulation runs generated by the automation, not retroactively.
Does Microsoft Attack Simulator require a specific license?
Yes, utilizing the Microsoft Attack Simulator requires an active Microsoft Defender for Office 365 Plan 2 license, which is typically included in enterprise subscriptions such as Microsoft 365 E5.




