I work at a small company that uses Microsoft 365 and want to run authorized phishing-awareness campaigns. The goal is to measure the campaign funnel—delivery, opens, clicks, and attempted form submissions—so we can identify weaknesses and provide better training. I have tested GoPhish with MailHog, but I'm having trouble creating convincing landing pages for scenarios such as password-expiration or account-reset notifications. I'm looking for recommendations on safe landing-page templates, purpose-built awareness platforms, architecture, or other resources. Microsoft Attack Simulation Training looks suitable, but our current licensing may not include it. Any advice for smaller organizations would be appreciated. The simulations should be clearly authorized, avoid collecting real credentials or sensitive data, and provide immediate educational feedback when someone interacts with a test.
5 Answers
A practical low-cost approach is to use a managed awareness platform if the budget allows, or GoPhish with a basic branded information page if it doesn’t. Whitelist the sending infrastructure carefully, coordinate with your mail and endpoint teams, document the approval and scope, and run a small pilot first. Avoid reverse-proxy or credential-capture tooling in an employee campaign; it creates unnecessary risk and can violate provider policies.
GoPhish works well if you want control and already have the operational pieces in place. For the landing pages, keep them simple and purpose-built: recreate the general layout and branding without copying a real login system, record only a click or a dummy interaction, and immediately explain that it was a simulation. Don’t request, transmit, or store real passwords, MFA codes, payment details, or other sensitive information.
KnowBe4, Hoxhunt, Huntress, and usecure are common alternatives for smaller teams. They provide professionally designed templates, campaign scheduling, reporting, and training content. Hoxhunt is particularly strong on polished templates and user-reporting workflows, while usecure offers customizable courses at a lower cost but requires more administration.
Before building everything yourself, check what your existing Microsoft 365 licensing includes. The built-in simulation features can handle delivery, tracking, landing pages, and follow-up training with much less maintenance than a custom GoPhish setup. Confirm the licensing and terms for every simulated user rather than trying to run it with a single license.
The quality of the training matters more than making the page indistinguishable from a real sign-in portal. Start with scenarios employees actually encounter, such as unexpected reset notices, invoice requests, or messages from executives, and measure reporting as well as clicks. Make the follow-up supportive rather than punitive so people are willing to report suspicious messages in the future.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures