How to train staff to spot fake Microsoft 365 login pages

A step-by-step guide to training staff to spot fake Microsoft 365 login pages: the six-second check, relay-kit traps, and a one-month reinforcement plan.

The email looks routine - a password expiry notice, a shared invoice, a voicemail. The link opens a page that is a pixel-perfect copy of the Microsoft sign-in: same logo, same blue button, same two-column layout. The staff member types their work email and password, approves an MFA prompt, and closes the tab feeling productive. Twenty minutes later their mailbox is sending invoice fraud on their behalf. Training staff to spot fake Microsoft 365 login pages is the highest-value habit in phishing awareness, because this one page is the front door to everything else.

TL;DR

Why this matters

A stolen Microsoft 365 password is not one stolen account. From a single mailbox an attacker can redirect payroll, read years of supplier history, send invoices with real thread context, and reset passwords for every service that trusts email. Microsoft sign-in is the bait of choice for a simple reason: almost every knowledge worker types their Microsoft password somewhere every day, so a request for it never feels strange.

Two details make fake login pages unusually effective. First, the artwork is trivially copied - attackers screenshot the real page and host it on a lookalike domain, so a visual test fails everyone. Second, adversary-in-the-middle kits have closed the last obvious tell: they proxy the real Microsoft page, collect the password, relay it to the genuine site, and hand the user a real MFA prompt. The user approves it, the attacker captures the session, and every red flag they were trained to watch for never appeared. The defence that survives both tricks is boring and positional: check where you are, not what it looks like.

Who this is for

MSPs training client workforces on Microsoft 365, and internal IT or people teams at businesses running Microsoft 365 without a dedicated security function. The method below assumes no tooling changes - it is a habit, a script for teaching it, and a way to measure whether it stuck.

What a fake Microsoft 365 login page actually looks like

The design is never the giveaway. Assume the attacker's copy of the page is indistinguishable from the real one - in most cases it is a screenshot or a proxied version of the genuine site. The differences live somewhere else:

The six-second check

This is the whole lesson. Give it a name so it sticks:

  1. Stop before typing anything. The password box is the finish line - reaching it means you already lost every checkpoint that mattered.
  2. Read the full domain, right to left, ending just before the first slash. login.microsoftonline.com is Microsoft's sign-in domain. login.microsoftonline.com.verify-mail.ru is not - everything before that first slash belongs to whoever registered verify-mail.ru.
  3. Ignore the padlock. A certificate proves the connection is encrypted, not that the site is Microsoft's. Every phishing kit ships with one.
  4. Navigate manually when in doubt. If the message claims to be about passwords, mailboxes or payroll, open the relevant app or type the known address yourself instead of trusting the emailed link.
  5. Report, do not just delete. A reported fake warns the colleagues who receive the same lure an hour later.
  6. When you already typed a password, say so immediately. Speed turns a breach into an incident. Reset, revoke sessions, move on - no blame.

How to train it in a month

  1. Week 1 - baseline. Run a phishing simulation with a credential-harvesting lure pointed at a fake sign-in. Do not publicise it beforehand. The click rate is your starting line, and the list of clickers is your coaching list - not your discipline list.
  2. Week 2 - the microlesson. One short module inside your security awareness training programme: the six-second check, two real-looking examples, done. Keep it under ten minutes; the habit matters more than the theory.
  3. Week 3 - variation. Run a second simulation with a different delivery: QR code in an attachment, a shared-document pretext, or the interstitial redirect. Same test, different coat, so staff learn the check rather than the example.
  4. Week 4 - measure. Compare click rates and, more importantly, report rates. Reporting rising while clicking falls is the real win - it means people are spotting and warning, not just avoiding.
  5. Ongoing - coach the repeaters. Anyone who clicks twice gets a five-minute walk-through, not an email warning. Anyone who reports gets visible credit. Culture decides whether the next person admits a mistake fast.

Common training mistakes

What to do next

The six-second check is a habit inside a programme, not a programme. If your training calendar is ad hoc, build the cadence first with security awareness training, then keep the credential-harvesting pressure constant through phishing simulations. If you need the business case written down before someone approves the budget, a gap assessment will show exactly how exposed a single mailbox leaves you.

FAQ

What is the real Microsoft 365 login page address?

login.microsoftonline.com for work and school accounts, login.live.com for personal Microsoft accounts. If the domain before the first slash is anything else, stop.

The page had a padlock and said secure - was it not safe?

No. A padlock only means the connection is encrypted. Phishing kits obtain valid certificates for free, so the padlock is meaningless as an identity check.

I got a real MFA prompt after signing in - does that mean the page was genuine?

Unfortunately no. Adversary-in-the-middle kits relay your login to the real Microsoft site, so the prompt you approve is real - but the attacker captures the session alongside you. An MFA prompt is not an authenticity stamp.

What should someone do if they already entered their password on a fake page?

Report it immediately - to IT, or to the MSP. Then reset the password and sign out of all sessions. If the report comes within minutes, the attack usually ends before it starts.

How often should we simulate fake login pages?

At least quarterly, rotating the lure and the delivery channel. Credential harvesting deserves the biggest share of simulation templates because it is the most common real-world attack.

Do technical controls make this training unnecessary?

They reduce volume, not risk. Mail filters miss novel domains, and no filter stops a person from typing a password into a proxied page they navigated to themselves. The human check is the last line that scales.

One last thing

Check whether password resets in your organisation are actually possible via emailed links. If your IT never sends expiry emails, say so publicly - a workforce that knows the real reset process never comes by email will flag that lure instantly, and attackers have one less story that works.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.