Security awareness training is one of the few security purchases a small business makes on behalf of people rather than machines, and it is the one most often bought badly. The usual failure is not the content library. It is that nobody decided who would send the phishing simulations, who would chase the twelve people who ignore every reminder, and who would explain the results to a client asking whether staff are trained. A platform can solve the first problem. Only a decision about ownership solves the other two.
This guide compares six platforms a business of roughly 10 to 250 employees can realistically buy and run: KnowBe4 Security Awareness Training, Hoxhunt, Huntress Managed Security Awareness Training, Proofpoint Security Awareness Training (ZenGuide), usecure, and the Attack Simulation Training built into Microsoft Defender for Office 365. It is written for the person who will actually own the programme, which in a small business is usually the owner, the office manager, or an outsourced IT provider.
How we compared these platforms
This is a documentation and pricing comparison. We did not run these platforms, we did not send test phishing campaigns, and we make no claim about which one changes behaviour fastest — no vendor publishes evidence in a form that would let anyone compare that honestly. What we did was read each vendor’s own administrator documentation, help centre and public price page, and record only what the vendor states in writing. Five things were checked for every platform:
- Published price. Whether a per-seat price exists on a public page. Where pricing is only available through sales, the table says so rather than guessing a number.
- Who runs the programme. Whether the vendor documents a fully managed service, or whether an administrator on your side builds and sends campaigns.
- Identity integration. Whether SAML single sign-on and automated user synchronisation (SCIM, Microsoft Graph, Google Directory or LDAP) are documented, because manual user lists are what quietly kill these programmes in year two.
- Phishing simulation. Whether simulated phishing is part of the product rather than a separate purchase.
- Buying route. Whether a small business can buy directly or is expected to go through a managed service provider or reseller.
Prices are the vendor’s own published list prices in USD, per seat per month, checked in 2026. Vendors change pricing and packaging without notice, so treat every figure below as the starting point for a quote rather than a guarantee.

Comparison at a glance
| Platform | Published price | Who runs it | SSO / user sync documented | Phishing simulation | Buying route |
|---|---|---|---|---|---|
| KnowBe4 Security Awareness Training | SAT Foundation $2.40, SAT Advanced $3.75 per seat/month at 25–50 seats, 3-year term MSRP; falls to $1.63 / $2.79 at 501–1,000 seats | Your administrator, in the KSAT console | SAML 2.0 SSO and SCIM both documented, including Microsoft Entra ID | Included | Direct or partner |
| Hoxhunt | Not published — quoted per employee by capability and headcount | Automated per-employee training paths; you own the programme | Entra ID SSO and SCIM documented; Google Workspace SSO documented | Included | Direct, via sales |
| Huntress Managed Security Awareness Training | Example pricing published: $1.75 per learner/month at 100 learners; calculator shows $2.08 at 50 learners | Fully managed by Huntress — vendor states managed learning programmes and phishing simulation | SCIM with Entra documented, plus Microsoft Graph, Google Directory, Okta and LDAP learner sync | Included | Direct, reseller (50-seat minimum per product) or MSP (no minimum) |
| Proofpoint Security Awareness Training (ZenGuide) | Not published — contact sales | Your administrator; Proofpoint offers premium and partner-assisted services | Entra ID SSO documented by Microsoft; SCIM for ZenGuide specifically not documented in public material we could verify | Included | Direct or partner |
| usecure | Not published — per-user, per-month, quoted on request; vendor states monthly billing, no minimum licences, no long-term commitment | Automated for you or run by your MSP; built for MSP delivery | SAML SSO documented for Entra ID, Okta and Google Workspace | Included (uPhish) | Mostly through MSPs; direct quotes available |
| Microsoft Defender for Office 365 Attack Simulation Training | Included with Defender for Office 365 Plan 2, listed at $5.00 per user/month paid yearly (Plan 1 is $2.00 and does not include it) | Your administrator, in the Defender portal | It is your identity platform — no integration needed | Included in Plan 2 | Direct from Microsoft or a CSP |
KnowBe4: the only platform here with a real price list
KnowBe4 publishes what almost nobody else in this category does: an actual per-seat price table you can read without talking to a salesperson. On a three-year term, SAT Foundation is listed at $2.40 per seat per month for 25–50 seats and SAT Advanced at $3.75, with both falling through published seat bands to $1.63 and $2.79 at 501–1,000 seats. Add-ons such as Compliance Plus and PhishER Plus are priced separately, and the published bands for those start at 101 seats.
On integration, KnowBe4’s knowledge base documents SAML 2.0 single sign-on for the training console and a SCIM integration for user provisioning, including a dedicated guide for Microsoft Entra ID, with Active Directory integration and Google user provisioning as alternatives. That combination is what lets a 60-person business stop maintaining a spreadsheet of learners.
Where it disappoints: the price you read assumes a three-year commitment, and the platform assumes an administrator. Campaigns, templates, remedial training and reporting are all things somebody at your end configures. If nobody at your business wants that job, the low seat price is not the relevant number.
Huntress Managed SAT: for businesses that want it taken off their hands
Huntress is the clearest answer to the ownership problem, because the vendor’s own description of the product is a managed one: fully managed learning programmes and phishing simulation, automated reporting, and rapid onboarding. It is also unusually transparent about price for a managed service — Huntress publishes example pricing of $1.75 per learner per month at 100 learners, and its pricing calculator shows $2.08 per learner at 50 learners.
The buying route matters here and is documented plainly: purchased through a reseller, Huntress states a 50-seat minimum per product; purchased through a managed service provider, there is no Huntress-required minimum. Learner management is well covered, with support articles for SCIM configuration in Microsoft Entra plus learner synchronisation from Microsoft Graph, Google Directory, Okta and LDAP.
Where it disappoints: managed means less control. If your compliance obligations require you to run specific campaign content on a specific schedule, a service designed to make those decisions for you is working against you. It also lands most naturally alongside the rest of the Huntress platform, so an organisation with no other Huntress product is buying into a vendor relationship, not just a training tool.
Hoxhunt: per-employee training paths, quote-only pricing
Hoxhunt’s model is individual rather than campaign-based: training and simulations adapt per employee rather than arriving as one quarterly blast to everyone. Its integration documentation is among the strongest in this group — the support centre covers Entra ID SSO and SCIM in a single guide, a separate guide covers Google Workspace SSO, and Microsoft publishes its own Entra provisioning tutorial for Hoxhunt.
The catch is commercial. Hoxhunt keeps its pricing off its public pages; its pricing page states only that pricing is per employee and depends on headcount and which capabilities you need. For a 30-person business that means you cannot budget for this platform without a sales conversation, and you cannot compare it against KnowBe4’s published table on equal terms.
Where it disappoints: no public price, and a design that assumes sustained participation. A per-employee adaptive programme is more valuable at 150 staff than at 12.
Proofpoint Security Awareness Training: capable, quoted, enterprise-shaped
Proofpoint’s awareness product, now presented under the ZenGuide name alongside the long-standing Proofpoint Security Awareness Training branding, sits inside a wider human-risk portfolio. Microsoft publishes an Entra ID single sign-on tutorial for it, and Proofpoint offers premium and partner-assisted services for organisations that do not want to run campaigns themselves. Pricing is not published anywhere public.
We could not verify, from public documentation, SCIM-based automated provisioning specific to ZenGuide, so we are not claiming it. If that matters to you, make the vendor confirm it in writing before signing — the same standard you would apply to any capability that appears in a slide deck but not in a manual.
Where it disappoints: the product and the sales process are built for organisations with a security team. A ten-person firm buying its first training platform will spend more time in procurement than in the product.
usecure: the MSP route, and the most flexible contract terms
usecure is built for delivery through managed service providers, which is exactly how a large share of small businesses buy security anyway. Its pricing page publishes commercial terms rather than numbers, and those terms are the most small-business-friendly in this comparison: per-user per-month pricing, monthly usage billing that scales up or down, no minimum licences and no long-term commitment. The actual rate comes from a quote.
The product set is modular — uLearn for training, uPhish for simulated phishing, plus policy management and dark-web monitoring — and the help centre documents SAML single sign-on setup for Microsoft Entra ID, Okta and Google Workspace, so identity integration is not limited to directory import.
Where it disappoints: if you have no MSP, you are buying a product designed around one. The multi-tenant tooling that makes usecure attractive to providers is irrelevant to a single business, and a direct customer gets none of the programme management an MSP would normally supply.
Microsoft Attack Simulation Training: already paid for, or a licence upgrade
If your business runs Microsoft 365, check your licences before buying anything. Attack Simulation Training in the Microsoft Defender portal lets you run real phishing simulations against your own users and assign training to the people who fall for them, including simulations delivered through Microsoft Teams. Microsoft documents it as a Defender for Office 365 Plan 2 capability.
That licence line is the whole decision. Microsoft lists Defender for Office 365 Plan 1 at $2.00 per user per month and Plan 2 at $5.00 per user per month paid yearly, and describes cyberattack simulation training as part of what Plan 2 adds over Plan 1. Microsoft 365 Business Premium includes Plan 1, so a typical small business on Business Premium does not have attack simulation today and needs the higher tier to get it.
Where it disappoints: it simulates and it trains, but it is not a behaviour-change programme with a content curriculum, and it does nothing for staff outside your Microsoft tenant. Treat it as excellent phishing simulation that you may already be close to owning, not as a full replacement for a training platform.

Which one fits your situation
- 25–100 staff, someone in-house willing to own it, needs a budget number today: KnowBe4. It is the only option you can price from a public page before talking to anyone.
- Nobody wants to own it: Huntress Managed SAT, or usecure delivered by your MSP. Both are explicitly built so the programme runs without you configuring campaigns.
- Already on Microsoft 365 and the immediate goal is phishing simulation: price the Defender for Office 365 Plan 2 upgrade first, then decide whether you still need a separate platform.
- Growing past 150 staff, repeat-clicker problem, budget for a quote process: Hoxhunt.
- Formal security programme, existing Proofpoint email security, procurement capacity: Proofpoint.
Three situations, and what we would actually do
A 12-person accountancy practice on Microsoft 365 Business Premium. The licence check comes first: Business Premium includes Defender for Office 365 Plan 1, so attack simulation is not available without moving to Plan 2 at the published $5.00 per user. At twelve seats that is a small monthly difference against buying a separate platform, so compare it directly with KnowBe4’s published seat pricing and pick on who will run it, not on price.
A 60-person construction firm whose IT is outsourced. Ask the provider what they already deliver. If they run usecure or Huntress, adding you to an existing platform is faster and cheaper than a new contract, and the reporting arrives without anybody at your office building it. Insist on seeing a sample report before you agree — the report is the deliverable a client questionnaire will eventually ask for.
A 200-person logistics business with one internal IT manager. Seat economics start to matter, and so does automated user synchronisation. KnowBe4’s published bands drop toward $1.63 per seat at 501–1,000 seats but you are well below that, and Hoxhunt becomes worth quoting at this size. The deciding question is whether your IT manager has three hours a month for the programme; if not, a managed service is cheaper than a platform that quietly stops being used.
What to confirm before you sign
- Contract term behind the advertised price. KnowBe4’s published figures are three-year term pricing; usecure publishes no-commitment monthly terms. These are not comparable numbers.
- Who sends the simulations. Get the answer as a named role, not as a feature. “Managed” means different things at different vendors.
- Whether user synchronisation covers your directory. SSO and automated provisioning are separate documents at every vendor here; confirm both for your specific identity provider.
- Minimum seats for your buying route. Huntress documents a 50-seat minimum via resellers and none via MSPs. Most other vendors state no public minimum at all, so ask.
- What the report looks like. Ask for a redacted real example. If it cannot answer “are our people getting better?” in one page, it will not survive contact with a client questionnaire.

A 30-day rollout that does not annoy everyone
Week one: baseline quietly. Synchronise users from your directory rather than importing a list, then run one simulation with no announcement and no consequences. You are measuring a starting point, not catching people. CISA’s small-business phishing guidance is a reasonable frame for what to test first, because it focuses on the handful of behaviours that actually stop an incident.
Week two: tell people what you are doing and why. Announce the programme after the baseline, share the aggregate result rather than individual names, and say explicitly that reporting a suspicious message is always the right move even when it turns out to be legitimate. NIST’s SP 800-50 Revision 1 is useful here as the reference for building a programme rather than running one-off events.
Week three: train, briefly. Short assignments for everyone, longer remedial content only for the people the baseline identified. Protect the calendar: fifteen minutes that people finish beats an hour they abandon.
Week four: measure and set the cadence. Run a second simulation, compare click and report rates against the baseline, and lock in a schedule you can sustain — monthly simulations and quarterly training is realistic for most small teams. Then write down who owns it. A programme with no named owner reverts to nothing within two quarters, whichever platform you bought.
Limitations of this comparison
- Four of the six vendors keep per-seat prices behind a sales conversation. Where a price is missing here, it is missing from the vendor’s public material, not omitted by us.
- Minimum seat counts are not documented publicly for most of these vendors; the Huntress reseller minimum is the exception.
- We make no claim about which platform reduces phishing susceptibility most. Vendor-published outcome statistics are not independently comparable, so we have excluded them.
- Capability we could not find in official documentation is marked as not documented rather than assumed — including SCIM specific to Proofpoint ZenGuide.
- Pricing and packaging in this category change frequently. Verify every figure against the vendor’s current page before you commit budget.
If identity is the next thing on your list, the same logic applies to sign-on: see our comparison of SSO solutions for small business, and our guide to endpoint security for small businesses with remote staff.
Sources
- KnowBe4 Security Awareness Training pricing — published per-seat MSRP by seat band and content level.
- KnowBe4 Security Awareness Training product page — training and simulated phishing scope.
- KnowBe4 Knowledge Base: set up SAML SSO — SAML 2.0 support for the training console.
- KnowBe4 Knowledge Base: configure SCIM for Microsoft Entra ID — automated user provisioning.
- KnowBe4 Knowledge Base: user management options — Active Directory, SCIM and Google provisioning.
- Hoxhunt pricing — per-employee, quote-based pricing model.
- Hoxhunt support: configuring Entra ID SSO and SCIM — SAML and SCIM configuration.
- Hoxhunt support: configuring Google Workspace SSO — Google identity support.
- Microsoft Learn: Hoxhunt automatic user provisioning — Entra provisioning tutorial.
- Huntress Managed Security Awareness Training — managed programme and simulation scope.
- Huntress pricing — example per-learner pricing and reseller versus MSP seat minimums.
- Huntress support: configure SAT SCIM in Microsoft Entra — SCIM provisioning.
- Huntress support: sync learners — Google Directory, LDAP, Okta and Microsoft Graph synchronisation.
- Proofpoint Security Awareness Training — product scope and services.
- Proofpoint human risk portfolio — positioning of awareness training within the wider suite.
- Microsoft Learn: Proofpoint Security Awareness Training SSO — Entra ID single sign-on.
- usecure pricing — per-user monthly billing, no minimum licences, no long-term commitment.
- usecure uPhish — simulated phishing capability.
- usecure help: set up SSO with Microsoft — SAML single sign-on.
- usecure help: set up SSO in Google Workspace — Google identity support.
- Microsoft Learn: get started with Attack Simulation Training — Defender for Office 365 Plan 2 requirement.
- Microsoft Learn: simulate a phishing attack — simulation and training assignment.
- Microsoft Learn: Teams-delivered simulations — simulation delivery beyond email.
- Microsoft Defender for Office 365 plans and pricing — Plan 1 and Plan 2 list pricing.
- Microsoft Defender for Office 365 service description — plan inclusion across Microsoft 365 subscriptions.
- CISA: teach employees to avoid phishing — priority behaviours for small businesses.
- CISA cyber guidance for small businesses — programme context.
- NIST SP 800-50 Rev. 1 — building a cybersecurity and privacy learning programme.