If you are having issues allowing the phishing simulation emails into Microsoft Exchange 365 using spam rules, you can use direct message injection (DMI).
Instructions on how to set this up are contained in the following article:
Direct Message Injection (DMI) Configuration Guide – Knowledge Base (knowbe4.com)