Enabling Auto-Enrollment for High-Risk Targets

This article describes the Auto-Enrollment for High-Risk Targets feature and explains how to configure it.

Overview

The Auto-Enrollment for High-Risk Targets feature automatically enrolls users who fail phishing simulations into remedial training campaigns after a phishing campaign ends. It applies to both ongoing and future phishing campaigns, allowing partners and organizations to quickly address risky behavior without manually creating remedial training campaigns.

How it works

Once a phishing campaign is completed, BullPhish ID identifies the users who failed the campaign. The campaign is considered complete once all training invites have been sent by the Send By Date and all results have been collected over the following three days, through the Close Date. The Close Date field on the phishing campaign’s Details page shows the date and time the campaign ended.

Failing a campaign is triggered by clicking a phishing link, submitting credentials, or both.

A remedial training campaign is then created automatically and the users who failed are enrolled. Email invites are sent immediately in the same language used for the phishing campaign. Each phishing campaign with failed users generates a corresponding remedial training campaign.

A remedial training course is assigned in the same language as the failed phishing test. If no training is available in that language, the course will be provided in US-English. Only global courses are used for remedial training; custom courses are not included.

Remedial training campaigns apply to all current and future organizations by default, but specific organizations can be excluded if needed.

Remedial training campaigns can be accessed on the View All Training Campaigns page. The Type column shows whether a campaign is Remedial or Standard and you can use this column to filter which campaigns are displayed.

Key considerations

  • If no users fail a phishing campaign, a corresponding remedial training campaign is not created.
  • Remedial training campaigns cannot be edited or recreated.
  • Pausing Auto-Enrollment does not affect ongoing remedial campaigns. Individual campaigns can be cancelled or deleted on the View All Training Campaigns page.
  • BullPhish ID and partner global training email templates are provided in multiple languages, with a default template pre-selected for each language.
  • You can preview, edit, or create new templates under Settings > Email Templates by selecting Training Type.
  • To reduce clutter, remedial groups are not created for high-risk users. Users who fail a phishing test are automatically enrolled in the appropriate remedial campaign, and all enrolled users can be viewed on the campaign’s Details page.
  • Data from remedial campaigns will not appear in business reports. For tracking and insights, generate a remedial campaign report from the campaign’s Details page. Remedial training data will be included in business reports soon.

Role permissions

The following describes the permissions granted to each role for the Auto-Enrollment for High-Risk Targets feature and remedial training campaigns.

Role Permissions
Partner Administrator/Partner Agent Full access to configure and manage Auto-Enrollment at both the partner and SMB level.
SMB Privileged User
  • Cannot configure or manage Auto-Enrollment.
  • Has the same permissions as the Privileged User has to a standard training campaign, except remedial training campaigns cannot be edited or recreated.
SMB Standard User
  • Cannot configure or manage Auto-Enrollment.
  • Has read-only access to remedial training campaigns.

Remedial Training Campaigns

When a phishing campaign is completed, BullPhish ID automatically creates a remedial training campaign for the high-risk users who triggered Auto-Enrollment.

View All Training Campaigns page

Remedial training campaigns are listed on the View All Training Campaigns page along with other training campaigns. The Type column shows how each campaign was created:

  • Remedial: Created automatically for high-risk targets after a phishing simulation.
  • Standard: Created manually by users with the necessary privileges, such as partner or organization administrators.

You can also use the Type filter to display only remedial campaigns.

IMPORTANT  Remedial training campaigns can be canceled, deleted, or resent but cannot be edited or recreated. The steps to cancel or delete a remedial training campaign are the same as for a standard campaign. For details, see the section Edit, cancel, or delete a training campaign in the article "Creating a training campaign."

Campaign details

The remedial training campaign’s Details page includes the following pre-defined fields:

  • Campaign Name: Remedial Training | [date and time of phishing campaign completion].
    Example: Remedial Training | 2025-04-11 14:45:34.561770
  • Phishing Campaign: A link to the phishing campaign that triggered the remedial training.
  • Schedule Frequency: Set to Once by default. Remedial campaigns are not recurring.
  • Start Date: This is the start date and time of the remedial campaign. The remedial campaign begins after the phishing campaign is completed, or on the next business day if Skip Weekends is enabled.
  • Expiration Date: The date and time the campaign will expire. Calculated based on Start date and time and the value selected for Additional Training Course Duration in the Auto-Enrollment modal.
  • Course Name: The name of the course assigned for the remedial training campaign.
  • Sending Profile: The sending profile selected in the Auto-Enrollment modal. All global training email templates provided by BullPhish ID or our partners are available for selection.

NOTE  For details about the View All Training Campaigns page and the campaign Details page, see the article Working with the Training & Awareness Dashboard.

How a course is selected

Only active global BullPhish ID courses are assigned. Custom courses created by the partner cannot be assigned. The most recently updated version of a phishing training course is assigned randomly in the remedial training campaign and determined by the following:

  • Kit language: The system looks for courses available in the language used for the phishing campaign.
  • Course Reassignment Timeframe: Courses already assigned within the selected timeframe are not reassigned.
  • Only active global BullPhish ID courses are assigned. Custom courses created by the partner cannot be assigned.
  • When there are no active courses available for the language, the system will assign an active US-English course.
  • When all existing active courses for the language have already assigned within the Course Reassignment Timeframe, the system will start to assign active courses from the language over again.
  • Although the system prioritizes selecting a phishing related training course for the campaign, it is possible that a compliance course could be assigned at this stage in the feature’s development.

How to...

 

Revision Date
Initial release. 9/25/25