Phishing attack simulation payload editor is extremely broken

Emil Gertsen Grønkjær 0 Reputation points
2025-01-14T12:22:45.53+00:00

We are using the attack simulation training module in Defender for Office.

So we have used the solution to run phishing exercises the past year.

I now wanted to change our custom positive reinforcement notification.
It seems the editor automatically removes all classes and a lot of the styling css content. Making it a living hell to design emails. This means I cant customize our content.

What is going on?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 2,090 Reputation points Microsoft Employee
    2025-01-20T12:11:45.4233333+00:00

    Hi @Emil Gertsen Grønkjær

    From my understanding, you are trying to edit an end user notification on the defender portal. It is possible to create new and edit Tenant notifications. Here is a link https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-end-user-notifications#modify-end-user-notifications

    I am unable to replicate your scenerio as I have the ability to edit and create end user notifications from the portal.

    1. You can use the import email button which activates choose File to select a new file (txt) which can replace the exisiting notifications.
    2. You can change the content by selecting text and adding any required text on the notification.
    3. Finanlly toggling to code allows for you to view and edit exisiting code.

    User's image

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.