I'm setting up a recurring phishing simulation program for about 250 mostly remote or hybrid employees split between Microsoft 365 and Google Workspace. The program needs to support future SOC 2, ISO 27001, or PCI audits, including automatic remedial training when someone clicks or fails a simulation and reliable records showing assignments, completions, dates, and campaign results.
I've looked at Microsoft Defender Attack Simulation Training, GoPhish, KnowBe4, Hoxhunt, CanIPhish, and a few other paid tools. I'd like practical feedback from people running these programs rather than vendor claims.
How have you handled delivery and allowlisting across both Microsoft 365 and Google Workspace? Has anyone maintained GoPhish long term, and how much ongoing ownership does it require? For paid platforms, what does pricing look like around 250 users, and do auditors care which product you use or mainly the evidence and workflow? Are smaller platforms such as CanIPhish worth considering?
4 Answers
GoPhish is capable, but it becomes an infrastructure and process ownership question. Hosting, mail delivery, updates, campaign design, reporting, and integrations all need a named owner. The basic simulation is straightforward; automatically enrolling failed users in training and maintaining audit-quality completion evidence are the parts you may have to build or connect yourself.
For a 250-person organization with two mail platforms, I’d only self-host it if someone has time to maintain it as an ongoing service. Otherwise, a paid product that supports both environments and exports campaign-level evidence may be cheaper in staff time, even if the license cost is higher.
KnowBe4 can automate the workflow you described. A failed simulation can immediately assign remedial training, and repeated failures can trigger additional training. You can also maintain separate mandatory training on a fixed schedule, such as every six months.
The reporting covers campaign results and user trends, and higher plans can tailor simulations by role or other user attributes. It’s useful if you want more than a basic mail-and-click test, although the more convincing simulations can make employees unhappy.
One quoted rate was roughly $1.97 to $3.19 per user per month on a three-year term, depending on the plan, though actual pricing varies with bundles and resellers. The organization in that discussion chose it partly because its insurer preferred the reporting, while another bundled product was considered more engaging.
The biggest issue with a split Microsoft and Google environment is making sure the messages are delivered consistently. Otherwise, your click rate may mostly measure which mail filter caught the simulation.
For Microsoft 365, use Defender’s supported Advanced Delivery configuration for third-party simulations rather than relying on a broad transport allow rule. That helps prevent Safe Links, ZAP, and other protections from altering the test. Google Workspace usually requires carefully scoped allowlisting or inbound-gateway rules, and those may need updating when the provider changes sending infrastructure. Avoid creating a wide exception that a real attacker could abuse.
For audit purposes, the product name usually matters less than being able to show who was targeted, who clicked, what training was assigned, and when it was completed. Pick the platform that produces those records cleanly across both environments.
There are smaller and MSP-oriented tools that support both Microsoft 365 and Google Workspace, including BullPhish and similar products. They can be worth evaluating if you want predefined templates, attack profiles, and integrations without paying for a large enterprise suite.
I’d make the evaluation practical: run a pilot in both environments and verify that simulations arrive consistently, links behave as intended, failed users are automatically assigned training, completion data is retained, and you can export a report showing the full chain of events. If a vendor cannot demonstrate that workflow during a pilot, a low license price probably won’t make up for the audit and administration gaps.

Also check whether the tool supports separate policies and reporting for each tenant. A single combined dashboard is convenient, but you still want to preserve which mail environment handled the campaign and whether filtering affected delivery.