Handbook

Teams Phishing Engagement Guide

NNathanUpdated 28 Sept 2026Services✎ Suggest a change
On this page

So, you have been assigned a Teams phishing campaign and don't know where to begin. Very good. Let's get started.

Things of note

Before we start here are a few things worth knowing.

  1. Decide with the client early in the campaign if you are using one of their internal accounts (i.e. business email/account compromise) or coming from an external position. If it's an internal user, the set up steps are redundant.
  2. Teams is configured to reject messages from Teams trial accounts by default. In theory we could ask the client to enable this temporarily, but generally speaking we don't like to lower their security if we don't have to so we need a licensed account.
  3. If you purchase a Microsoft 365 licence and cancel it within 7 days you are unlikely to be charged for it. This means if we can get the engagement completed within those 7 days and cancel the licence and tenancy we don't incur costs.
  4. Domain reputation does not have any influence on this style of engagement. We can use any that we like and it can be as new as we like. The client also does not need to whitelist us by default.
  5. Generally speaking we will only buy the one licence. This means you may have to reassign the licence to a different user to use a different pretext. Try to consolidate your pretexts where possible to use the least amount of users and maximise the amount of response time the victim has.
  6. If you have a target who is on the IT helpdesk, try to target them first. When complete, the client contact can let them know its an authorised phishing campaign, and they will be unlikely to block further communicates or send out a warning email to staff.

TL;DR

Detailed steps are available below. But for now this is what you have to do:

  • Obtain a list of targets from the client (it is better if they do not regularly communicate with each other i.e. different departments or locations)
  • Register a domain (reputation doesn't matter)
  • Create a Microsoft 365 tenancy
  • Join the domain to the Microsoft 365 tenancy
  • Purchase a Microsoft 365 Business Standard licence
  • Perform some OSINT and find potential users you can impersonate
  • Develop relevant pretexts
  • Confirm schedule and "success" criteria with client (e.g. Target doesn't respond within 4 hours)
  • Send messages
  • Pray (to whichever deity you prefer) or make a sandwich
  • Document results and write report
  • Cancel licence and tenancy

Set up

Unlike email phishing we do not need to worry too much about domain reputation for this. This means we can do it all rather quickly, and in most cases quicker is better to save on costs where possible.

We are going to need the following:

  • A domain registered for the campaign
  • A Microsoft 365 tenancy
  • A Microsoft 365 Business Standard licence

I am going to make the assumption here that you know how to register a domain. If you don't, have a look at the other phishing guides or ask a team member to help you. You can use any registrar for this purpose, it doesn't matter. The only thing you need is to have access to the domain name servers so you can edit the DNS records.

Let's assume you have registered evilphishing.com for this campaign. When registration is complete ensure you have configured the domain for DNS hosting (AWS, Cloudflare, whatever, doesn't matter).

The tricky part is setting up the Microsoft 365 tenancy. This process changes regularly so screenshots wont be much help. But the gist of it is:

  1. Go to Settings > Domains (you may need to "show more" to see this)
  2. Add the domain
  3. Copy out the TXT record and add it to your DNS records
  4. Click the Verify button
  5. Wait for confirmation

Once the domain is verified you can create users with email addresses using that domain. In order for them to actually use Teams, they will need a Microsoft 365 licence. Business Standard is currently the cheapest way to do this and requires the least set up.

You can purchase as many licences as you need, but generally speaking one is enough as you can transfer it between users as required.

At this point I recommend sending a test message from a test account to the client contact to confirm receipt and that the campaign can go ahead. No point in going ahead if they can't accept the communication.

If they cant receive the messages, they will either need to lower their security slightly to allow external communications or the campaign will need to be changed to an internal account.

Pretexts

Once we have our infrastructure in place, we need to develop our pretexts. The first thing we want to do is some research on our targets.

Ideally we will have a list of 5-10 targets from different departments. You can choose between a generic pretext for all targets or tailored ones for each. Generally speaking tailored is better and more likely to get a response.

First thing to do is to do some OSINT research on each user. You can often view a user's LinkedIn profile unauthenticated using Google cached pages and the WayBack machine. Additionally, you can look for Facebook/Instagram/etc. What we are looking for is their current role, who they may associate with, and what kind of work they do day to day. We can then use that to build our pretext.

E.g. If one of our targets is in payroll, we may want to try and see if we can get them to change a user's account details or provide information on which superannuation fund they are using. We wouldn't want to try this on someone working in inventory management though.

Put together a list of targets and the pretext you are going to use for each.

Next we need to determine who we are going to impersonate. We perform some additional OSINT, looking for individuals that may interact with the target. E.g. Managers, IT team members, suppliers, etc.

We want to steal any profile picture we can get and any details we may see in Teams:

  • First and last name
  • Email address
  • Job title and description
  • Approximate location/time zone

We create each account in our Microsoft 365 admin portal with the appropriate information. Make sure to take note of each email address and password you create.

if possible we want to use the same person for multiple targets, this speeds up the campaign significantly as you can send multiple messages at the same time.

The Cam-pain

Now we are ready to roll. We confirm the time of the campaign with our client contact and ensure they are ready to go should shit hit the fan.

Assign the licence you purchased to your first user, and log in to Teams. This can take a few minutes between transferring the licence and teams being ready to go, so some patience is required.

Once logged in, make sure your account has all the right details (profile picture, user details, etc). Then get ready to send your message.

The process from here is simple:

  1. Send message
  2. ????
  3. Profit (Report findings)

If the target responds to your message, you will need to put your best acting hat on. You need to build up some trust quickly then get some details. What those details are depends on the target, the pretext, and the goal of the campaign.

A "pass" may be categorised as:

  • Did not respond at all within the designated time frame
  • Reported the phishing attempt to the client contact
  • Did respond but quickly shut the conversation down
  • Did respond but refused to give any details

If you, as the attacker, are successful in obtaining the details, the target can be listed as a "fail" for now.

Continue rotating the software licence between users and making your initial contact until you have sent messages to all targets.

Reporting

Reporting for Teams phishing is the same as email phishing. You need to include screenshots of your pretexts and how you set up your users.

Include screenshots of user responses if you get any. If not, then it may be in your interest to demonstrate why, by including screenshots of the warnings the user is presented with before accepting the message.

Clean up

Once you are done with the technical part of the campaign you will need to cancel your licence and delete your tenancy.

Cancelling the licence is a bit of a pain, it seems to move it's location regularly. As of the time this was written, you need to go to Admin > Billing > Licences and cancel the subscription.

It may take a while for the subscription to fully cancel.

As for the tenancy itself, I am still trying to work that out. Microsoft support have not been particularly helpful here. It may be that i have to wait until the "renewal" period expires (i.e. one month from purchase) before the subscription is removed. I will update it when i have accurate details.