From Phishing Simulation › Setup you can configure your company's phishing simulations and make them operational: grant LibraCyber permission to send emails, verify that simulations arrive, customize templates, and activate sending. The procedure is straightforward and takes approximately 20-30 minutes. It takes place across four tabs on the Setup page — Setup Checklist, Delivery Test, Template Attribution, and Preferences — plus your company profile in Phishing Simulation › Company Scan.
Prerequisites
- Phishing Simulation is enabled for your company. This is a per-company activation managed by LibraCyber; until it is active, the Phishing Simulation area does not appear in the console.
- Users and departments already synchronized on the platform, from General Settings › Users provisioning: simulations are directed to users and departments, so the user list and departments must already be present.
- Email integration / sending domain configured: LibraCyber must be authorized to send emails through your Google Workspace or Microsoft 365 tenant.
- Setup permission to access the Setup page; to complete the company profile you also need the Company Scan permission. Both are assignable and revocable by your company.
NOTE: access has Trial, Full, and No access levels; some preferences appear only with Full access (see step 6).
Detailed procedure
Open the Setup page
Open Phishing Simulation › Setup. The Simulation Setup page displays four tabs: Setup Checklist, Delivery Test, Template Attribution, and Preferences. If the entire Phishing Simulation area does not appear, your company does not have the enablement or lacks the Setup permission.
Complete the Setup Checklist
In the Setup Checklist tab, work through each item until it turns green. There are five items:
- API sending permission — grant LibraCyber permission to send simulations through your tenant. On Microsoft 365 use Grant API Permissions, which takes you to General Settings › Users provisioning, where the permission is actually granted. On Google Workspace follow the How to grant Consent guide (service account consent).
- Provisioning of at least one additional user — with Go to User Provisioning, add at least one non-administrator user. The item changes to It works!.
- Delivery Test — redirects to the Delivery Test tab (step 4), to verify that users can complete simulations.
- Template attribution to departments — redirects to the Template Attribution tab (step 5), to assign at least one template to departments.
- Report Button — with Go to installation guide (Gmail or Outlook), distribute the phishing report button to all users, then confirm with an acknowledgment checkbox.
Complete the company profile (Company Scan)
Open Phishing Simulation › Company Scan. Despite its name, it is a configuration screen, not an external company scan. Complete its contents:
- key people (for example CEO, CFO, CPO, HR, sales director, and IT manager);
- the company signature;
- key clients.
This data powers personalization macros that make simulations credible (for example a fake message "from the CEO"). You can modify them at any time.
Run the Delivery Test
Open the Delivery Test tab and send yourself test simulations with Send all test simulations (or one at a time). For each simulation complete the entire flow: click the link, enter credentials, download the file, open the attachment, or grant the required permissions. Each test simulation must arrive in your mailbox and display correctly; the Delivery Test item in the checklist changes to It works!.
WARNING: Send all test simulations performs real sends to your mailbox, not silent previews. The button is disabled in an MSP session (partner): in that case it displays the message "Not available in MSP mode".
Assign templates to departments (Template Attribution)
Open the Template Attribution tab and assign templates to departments, so each group receives simulations relevant to the tools they use. The corresponding item in the checklist changes to It works!. You can re-assign templates later.
Configure Preferences
Open the Preferences tab and set up your program. Each tab saves itself when modified: there is no separate Save button. The visible tabs depend on your access level (Full access displays all of them).
- Sending onboarding emails to new users — new employees receive an email explaining how LibraCyber's phishing simulations work, along with an initial test simulation. With Send example onboarding email to myself you can send yourself an example first.
- Automatic simulation sending — this is the always-active program: employees receive simulations automatically based on template attribution, on business days and during business hours.
- Minimum interval between two simulations — a slider from 1 to 90 days. The actual interval for each user is randomly varied between the set value and its double (for example setting 20, the next simulation arrives between 20 and 40 days apart), so simulations are unpredictable.
- Include trial campaigns in Dashboard metrics — active by default; applies to anyone accessing the Dashboard in your company. Disable it to keep test or audit results out of Dashboard numbers.
- Landing page override — when active, anyone clicking a simulation sees an anonymous 404 page instead of the training form. This is an audit/red-team setting, not normal mode.
- Erase all simulation data — the Erase all simulation data button removes already-sent simulations from Dashboard statistics. The confirmation window warns that the operation is irreversible and offers Download all simulation data to back up your data first.
WARNING: enabling Automatic simulation sending starts real simulation sends to employees. Enabling Sending onboarding emails to new users in an already-operational company sends onboarding (plus a test simulation) to all active users who have never received it, not just new hires. You can disable these toggles later, but emails already sent cannot be recalled.
Expected result
At this point all items in the Setup Checklist show a green checkmark or It works!, a test simulation has arrived correctly in your mailbox, and — with Automatic simulation sending active — the Dashboard begins to populate in the following days as emails are sent. Your company is ready to receive phishing simulations.
Troubleshooting
| Symptom | Probable cause | Solution | Escalation |
|---|---|---|---|
| The Phishing Simulation area or Setup page does not appear | The product is not enabled for your company, or you lack the Setup permission | Ask LibraCyber to confirm enablement; have your administrator assign the Setup permission in General Settings › Permissions | — |
| The Preferences tab shows "Your company doesn't have access to phishing simulations", or almost all tabs are missing | Your access level is No access, or Trial (which hides tabs reserved for Full access) | Ask LibraCyber to activate Full access if you need the complete set of preferences | — |
| The API sending permission item remains red | Sending permission has not been granted on your directory | Complete the Grant API Permissions flow (Microsoft) or How to grant Consent (Google) in General Settings › Users provisioning | Contact LibraCyber support if the item remains red |
| Send example onboarding email to myself or Send all test simulations is disabled (grayed out) | MSP session (partner) — the button displays the message "Not available in MSP mode" | Log in directly to the customer company (not the MSP view) to perform the send | — |
| A test simulation never arrives | Incomplete sending permission, or the provider filtered the message | Verify that the sending permission item is green; check your spam/quarantine folder; send again | Contact LibraCyber support if the problem persists |
| The Delivery Test item remains orange ("Some simulations aren't fully tested yet") | Not all simulation flows have been completed | Complete the entire flow (click, credential entry, download, attachment opening, permission granting) for each simulation | — |
| Template previews show empty names instead of CEO or CFO | Key people or signature in the company profile (Company Scan) are not filled in | Complete Company Scan (key people and signature), as in step 3 | — |