Skip to main content

How to Onboard a New Security Awareness Training Client in Under 5 Minutes

, CEO
MSP onboarding a new security awareness training client efficiently in under 60 minutes

How to Onboard a New Security Awareness Training Client in Under 5 Minutes

You can onboard a new security awareness training client in under 5 minutes of MSP time. Add the client, connect their directory, safelist the simulations, and confirm Autopilot. On Hook, adding the client configures and launches their program in one click. Everything else is a short checklist.

That matters because an hour is a long time to an MSP. Multiply it by every new logo and every client that renews, and onboarding stops being a task and starts being a reason not to sell the service at all.

The 5-minute onboarding flow

Add the client and launch (about 1 minute). From Clients in the Hook MSP portal, add the new client. One click configures their program and launches it. The client shows up in your portfolio next to everyone else, and you can open their portal from there without a second sign-in.

Connect their directory (about 2 minutes). Connect the client's Microsoft Entra ID or Google Workspace so their people sync automatically, then pick the groups to include. Hook asks for read-only access and never write access. Someone who can grant consent for the client's tenant has to approve it, so send the request while you're on the phone with their admin. No directory? Import a CSV instead.

Safelist the simulations (about 1 minute). Send the client's mail team the values they need to allowlist: Hook's fixed sending IPs and the sender domain for the templates you'll use. On Google Workspace, Google Direct Send can deliver simulations straight to the inbox once a super admin approves it.

Confirm Autopilot (about 1 minute). Check the cadence (monthly, every two months, or quarterly), the audience, and who gets a preview before each simulation goes out. Add the client's champion as a preview contact so nothing reaches their people as a surprise.

That's the whole job: about 5 minutes of your time, and the client is live.

What still takes time, and why it isn't yours

Two steps involve waiting, not working. The client's identity admin has to approve the directory consent, and if you use Google Direct Send, Google can take up to 24 hours to apply the delegation. Neither one needs you to stay on the screen. Your 5 minutes are done; the calendar does the rest.

Everything that usually eats an MSP's onboarding hours is gone. You don't build the program: Autopilot schedules the simulations and training. You don't pick content for each client. You don't build reports from scratch, and you don't train the client's champion to run a console. They get previews and results by email instead.

The step people skip: safelisting

If one thing goes wrong in month one, it's this. When the client's mail filter quarantines a simulation, nobody sees it. The report comes back looking great, and it's wrong: the numbers say the client is doing well because the email never arrived.

Do it during onboarding, not after the first results look odd. Hook's safelisting guide lists the eight IP addresses and explains where to find each template's sender domain. Hand it to whoever runs the client's email security, and repeat it any time you start using a template that sends from a new domain.

Where Hook fits

Hook is a security awareness training and phishing simulation platform built for MSPs and SMBs. The MSP portal puts every client in one directory with a one-click launch. Directory sync keeps enrollment current as people join and leave. Autopilot runs the monthly cadence of simulations and training, and every click becomes a Training Moment instead of a log entry. Hundreds of MSPs run their clients this way. Hook prices per seat with every feature included; MSP partner pricing is available on request.

Still choosing a platform? The MSP buying guide lists the criteria to test in a demo. Ask every vendor to onboard a client live while you watch the clock.

Frequently asked questions

Can you really onboard a security awareness training client in 5 minutes?

Yes, in MSP time, on a multi-tenant platform. Adding and launching the client is one click, and the directory, safelisting, and Autopilot steps take a minute or two each. Calendar time can be longer, because the client's admin has to approve directory access and Google can take up to 24 hours to apply Direct Send.

What does the client have to do?

Three things: approve the directory connection, have their mail team add the safelisting rules, and name a champion who gets previews and reports. That's it. Keeping the client's list this short is most of why launches stop slipping.

When does the first phishing simulation go out?

When Autopilot's next cycle comes around, on the cadence you chose. The Autopilot page shows the date before anything sends, and preview contacts get a heads-up first. Tell employees the program exists before the first simulation lands. People who know it's coming treat it as practice, and that's the tone the whole program should have.

Do employees need a new login?

No. They take training from emailed links, and you can add single sign-on later with Microsoft Entra ID, Okta, Google Workspace, or any SAML 2.0 provider.

Keep reading

Ready to Strengthen Your Security Culture?

See how Hook Security can help protect your organization.