The email looks routine - a password expiry notice, a shared invoice, a voicemail. The link opens a page that is a pixel-perfect copy of the Microsoft sign-in: same logo, same blue button, same two-column layout. The staff member types their work email and password, approves an MFA prompt, and closes the tab feeling productive. Twenty minutes later their mailbox is sending invoice fraud on their behalf. Training staff to spot fake Microsoft 365 login pages is the highest-value habit in phishing awareness, because this one page is the front door to everything else.
TL;DR
- The real Microsoft 365 sign-in lives at login.microsoftonline.com - the domain in the address bar is the one test page design cannot fake.
- Modern credential kits relay logins to the real Microsoft site, so a genuine MFA prompt after signing in is not proof the page was safe.
- Train the six-second check: stop, read the full domain, sign in manually if unsure.
- The padlock icon proves encryption, not ownership - anyone can get one.
- Reinforce the habit with simulations that use the same lures, and coach repeat clickers instead of punishing them.
Why this matters
A stolen Microsoft 365 password is not one stolen account. From a single mailbox an attacker can redirect payroll, read years of supplier history, send invoices with real thread context, and reset passwords for every service that trusts email. Microsoft sign-in is the bait of choice for a simple reason: almost every knowledge worker types their Microsoft password somewhere every day, so a request for it never feels strange.
Two details make fake login pages unusually effective. First, the artwork is trivially copied - attackers screenshot the real page and host it on a lookalike domain, so a visual test fails everyone. Second, adversary-in-the-middle kits have closed the last obvious tell: they proxy the real Microsoft page, collect the password, relay it to the genuine site, and hand the user a real MFA prompt. The user approves it, the attacker captures the session, and every red flag they were trained to watch for never appeared. The defence that survives both tricks is boring and positional: check where you are, not what it looks like.
Who this is for
MSPs training client workforces on Microsoft 365, and internal IT or people teams at businesses running Microsoft 365 without a dedicated security function. The method below assumes no tooling changes - it is a habit, a script for teaching it, and a way to measure whether it stuck.
What a fake Microsoft 365 login page actually looks like
The design is never the giveaway. Assume the attacker's copy of the page is indistinguishable from the real one - in most cases it is a screenshot or a proxied version of the genuine site. The differences live somewhere else:
- The domain. Real Microsoft sign-ins happen on login.microsoftonline.com (and login.live.com for personal accounts). Fakes ride on lookalike or unrelated domains - extra words, swapped letters, or a Microsoft name buried mid-domain.
- The route in. The link arrives by email, a Teams message, a QR code on a document, or a shared-file notification. A QR code is just a link that dodges the email scanner - treat it the same.
- The story. Expiring passwords, unread voicemails, shared payroll documents, bonus letters, shipping notices. None of these are real signals; they are whichever pretext gets the click.
- The interstitial. Some campaigns open a benign-looking preview first and redirect to the fake sign-in on the second click, which breaks the habit of judging a link by its landing page.
The six-second check
This is the whole lesson. Give it a name so it sticks:
- Stop before typing anything. The password box is the finish line - reaching it means you already lost every checkpoint that mattered.
- Read the full domain, right to left, ending just before the first slash. login.microsoftonline.com is Microsoft's sign-in domain. login.microsoftonline.com.verify-mail.ru is not - everything before that first slash belongs to whoever registered verify-mail.ru.
- Ignore the padlock. A certificate proves the connection is encrypted, not that the site is Microsoft's. Every phishing kit ships with one.
- Navigate manually when in doubt. If the message claims to be about passwords, mailboxes or payroll, open the relevant app or type the known address yourself instead of trusting the emailed link.
- Report, do not just delete. A reported fake warns the colleagues who receive the same lure an hour later.
- When you already typed a password, say so immediately. Speed turns a breach into an incident. Reset, revoke sessions, move on - no blame.
How to train it in a month
- Week 1 - baseline. Run a phishing simulation with a credential-harvesting lure pointed at a fake sign-in. Do not publicise it beforehand. The click rate is your starting line, and the list of clickers is your coaching list - not your discipline list.
- Week 2 - the microlesson. One short module inside your security awareness training programme: the six-second check, two real-looking examples, done. Keep it under ten minutes; the habit matters more than the theory.
- Week 3 - variation. Run a second simulation with a different delivery: QR code in an attachment, a shared-document pretext, or the interstitial redirect. Same test, different coat, so staff learn the check rather than the example.
- Week 4 - measure. Compare click rates and, more importantly, report rates. Reporting rising while clicking falls is the real win - it means people are spotting and warning, not just avoiding.
- Ongoing - coach the repeaters. Anyone who clicks twice gets a five-minute walk-through, not an email warning. Anyone who reports gets visible credit. Culture decides whether the next person admits a mistake fast.
Common training mistakes
- Teaching regex rules. Staff cannot parse domain trees under pressure. Right-to-left reading of one domain is a habit; a mental parser is not.
- Venerating the MFA prompt. Training that treats the MFA notification as proof of safety is worse than none - it is exactly what relay kits exploit.
- Punishing clicks. Every hidden click is an unreported compromise. Reward speed of reporting above all else.
- One-and-done. A single session decays in weeks. The habit survives on simulations sprinkled through the year, not on a February workshop.
What to do next
The six-second check is a habit inside a programme, not a programme. If your training calendar is ad hoc, build the cadence first with security awareness training, then keep the credential-harvesting pressure constant through phishing simulations. If you need the business case written down before someone approves the budget, a gap assessment will show exactly how exposed a single mailbox leaves you.
FAQ
What is the real Microsoft 365 login page address?
login.microsoftonline.com for work and school accounts, login.live.com for personal Microsoft accounts. If the domain before the first slash is anything else, stop.
The page had a padlock and said secure - was it not safe?
No. A padlock only means the connection is encrypted. Phishing kits obtain valid certificates for free, so the padlock is meaningless as an identity check.
I got a real MFA prompt after signing in - does that mean the page was genuine?
Unfortunately no. Adversary-in-the-middle kits relay your login to the real Microsoft site, so the prompt you approve is real - but the attacker captures the session alongside you. An MFA prompt is not an authenticity stamp.
What should someone do if they already entered their password on a fake page?
Report it immediately - to IT, or to the MSP. Then reset the password and sign out of all sessions. If the report comes within minutes, the attack usually ends before it starts.
How often should we simulate fake login pages?
At least quarterly, rotating the lure and the delivery channel. Credential harvesting deserves the biggest share of simulation templates because it is the most common real-world attack.
Do technical controls make this training unnecessary?
They reduce volume, not risk. Mail filters miss novel domains, and no filter stops a person from typing a password into a proxied page they navigated to themselves. The human check is the last line that scales.
One last thing
Check whether password resets in your organisation are actually possible via emailed links. If your IT never sends expiry emails, say so publicly - a workforce that knows the real reset process never comes by email will flag that lure instantly, and attackers have one less story that works.