1. Watch for fake login pages
- Only sign in through official apps (Outlook, Teams, gmail, etc.) or by typing the address yourself.
- Never sign in via a link in an email or chat message, even if it looks like Microsoft.
- Check the web address carefully before entering your password — attackers use lookalike domains.
2. Be suspicious of "urgent" MFA prompts
- If you get an MFA approval request you didn't trigger, deny it and report it — don't tap Approve just to make it stop.
- Repeated unexpected MFA prompts usually mean someone already has your password.
3. Use a password manager
- Don't reuse passwords across sites.
- A password manager won't autofill on a fake/lookalike site — that's a useful warning sign itself.
4. Keep your device clean
- Don't install software from outside official app stores.
- Keep your OS and browser updated.
- Don't ignore antivirus/security alerts.
5. Never share verification codes
- IT or Microsoft will never ask you for your MFA code over phone, email, or chat.
- If someone asks for one, it's a scam — hang up / stop replying and report it.
6. Report anything odd immediately
Contact IT right away if you notice:
- A login prompt you didn't expect
- Emails you didn't send in your Sent folder
- New inbox rules you didn't create
- Your account signed in from an unfamiliar location or device
When in doubt, report it — acting fast limits the damage.
Comments
0 comments
Article is closed for comments.