How to Configure a Custom Phishing Link in Attack Simulation Training?

Implement and manage email and collaboration protection by using Microsoft Defender for Office 365
Answer Correct answer: A — Create a tenant payload so the credential harvest simulation email includes a custom phishing link with company terminology and branding.

You have a Microsoft 365 E5 subscription and use Microsoft Defender for Office 365. You are configuring Attack simulation training that will target all users and use the Credential Harvest social engineering technique. You need to ensure that the simulation sends an email message that contains a custom phishing link and company-based terminology and branding. How should you configure the simulation?

  1. Create a Tenant payload. Correct Answer
  2. Select a Global payload.
  3. Select custom end-user notifications.
  4. Create a tenant landing page.

Community Votes

A
65%
C
35%

65% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests whether you know that custom phishing email content is defined by a tenant payload, not by global payloads, landing pages, or end-user notifications — the trap is choosing C because it also sounds like customization.

Attack simulation training in Microsoft Defender for Office 365 uses payloads to define the phishing email content. This page establishes that a tenant payload (A) is required to include a custom phishing link plus company terminology and branding, while global payloads, landing pages, and end-user notifications cannot do that.

Choosing C (custom end-user notifications), because it also offers customization; however, end-user notifications control post-simulation training and reminder messages, not the phishing email body or its embedded link.

Community Discussion (8 comments)

hola1010 👍 6 Selected: A
It's A. https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-payloads See creating payloads. C is used for notifications about training, positive reinforcement etc.
Xive 👍 5 Selected: A
Create a Tenant Payload. You can't use Global payload, this are built in payload so cannot be custom. question ask for custom phishing link
Ody 👍 3
A Tenant payload
mido3100 👍 2 Selected: C
C is correct, end-user notification
Preeb 👍 2
To configure the Attack simulation training to target all users with a custom phishing link and company-based terminology and branding, you should choose: B. Select a Global payload. This option allows you to utilize a standardized phishing simulation that can be customized with your company’s branding and terminology, ensuring the simulation is effective and relevant to your users.
joaquim.gomes.pt 👍 2 Selected: C
https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-end-user-notifications
GetEsn 👍 2 Selected: C
https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-end-user-notifications
GetEsn 👍 1
https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-end-user-notifications

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Attack simulation training in Microsoft Defender for Office 365 separates the simulated email from the landing page and the follow-up notifications. A tenant payload is the customizable email template created inside your own tenant, and it is the component that carries your custom phishing link, sender details, subject, body text, and company-specific terminology and branding. The question explicitly asks for the email message to contain a custom phishing link and company-based terminology, which maps directly to a tenant payload (A). By contrast, a global payload is a Microsoft-provided template that cannot be edited to insert your own link or branding.

Why the Other Options Are Wrong

Option B fails because global payloads are read-only, out-of-the-box templates; you cannot add a custom phishing link or your company's terminology to them. Option C refers to custom end-user notifications, which are the messages users receive about training assignments, reminders, or positive reinforcement — not the simulated phishing email itself. Option D, a tenant landing page, customizes the web page a user sees after clicking the simulated link; it does not define the email message or its embedded phishing URL.

Community Comment Notes

hola1010 correctly noted "It's A." and pointed to the payloads documentation while explaining that C is used for training notifications. Xive reinforced this, stating "You can't use Global payload, this are built in payload so cannot be custom." and emphasising that the question asks for a custom phishing link. Several learners (mido3100, joaquim.gomes.pt, GetEsn) voted C and linked the end-user notifications article, but that documentation covers user-facing training messages, not payload creation. Preeb suggested B, yet global payloads are built-in and non-editable, so B cannot satisfy the custom-link requirement.

Official Reference

Exam Strategy

Focus on where each customization lives: payloads define the email template and link, landing pages define the post-click web page, and end-user notifications define training or reminder messages. When a question mentions an 'email message' with a custom link and branding, pick tenant payload.

Frequently Asked Questions

Why isn't the tenant landing page (D) the answer?

A landing page controls the web page shown after a user clicks the simulated link; it does not compose the phishing email, its link, or the message branding.

Can I edit a global payload to add a custom phishing link?

No. Global payloads are Microsoft built-in templates that cannot be modified; create a tenant payload when you need a custom link, sender, or company terminology.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide