What just happened

The "Microsoft security" email you received was not from Microsoft. It was a safe, internal phishing simulation run by our security team. If you clicked the link and entered your credentials, no real account was compromised and no password was stored. But had this been a real attack, an outsider could now have access to your account.

The good news: this is exactly the moment to learn the warning signs so the real thing does not catch you.

Red flags you can catch next time

What to do when you spot one

Everyone is learning, and phishing simulations are how we practice together so the whole organization gets harder to fool. Thank you for taking a minute to read this.