Lesson 5 of 7, about 3 minutes

Fake sign-in pages and sign-in codes

Where passwords get stolen, and how sign-in approvals get abused.

Many phishing messages lead to a page that looks like your Microsoft 365 sign-in. If you type your password there, the criminal has it. If you also approve a prompt or read out a code, they can get in.

Before you type a password

  • Check the address bar. Real Microsoft sign-in pages end in microsoftonline.com, microsoft.com or live.com.
  • Do not sign in from a link in a message you did not expect. Type office.com yourself.
  • Be suspicious of a page that asks you to sign in to view a document you never asked for.

Sign-in prompts and codes

  • Only approve a prompt you started yourself. If your phone asks you to approve a sign-in you did not start, tap Deny.
  • If the app asks you to type a number and you are not signing in, deny it.
  • Never read out a sign-in code, or type it anywhere except the page you opened yourself.
  • Nobody who is helping you needs your code or your approval.

Try it. Your phone asks you to approve a sign-in. You are not signing in anywhere. What do you do?

Good to know

If you already fell for it, change your password from another device and tell us right away. Speed makes a large difference.