
Workplace MODULE
Protecting your work account
The account is the real target. Learn what your provider actually does.
Your work account is the thing attackers want, whether your organisation signs in with Microsoft 365 or with Google Workspace. This module covers the four ways such an account is actually taken, including the attacks that keep working when multi-factor authentication is switched on.
- Tell a genuine notification from your provider apart from an imitation of one.
- Recognise the sign-in, code and permission requests that defeat multi-factor authentication.
- Verify and report a suspect message without needing a technical background.
Your learning path
01The name worth borrowingRecognise what a genuine message from your provider does, and what it rarely does.Locked02The sign-in page that keeps your passwordUnderstand why a perfect copy of a sign-in page defeats both a strong password and a code.Locked03The code you were asked to typeRecognise device code phishing, where every page you see genuinely belongs to the provider.Locked04Permission is not the same as a passwordRecognise a consent request that hands over access without ever asking for credentials.Locked05When it appears to come from insideApply the same checks when a message appears to come from a colleague or from your own organisation.Locked06Check it, report it, recover from itAct confidently after a suspicious message, including when you have already clicked.LockedPut your decisions into practice.
Complete each lesson’s scenario, then take eight new questions. A score of at least 80% earns a personal completion record. Retry with feedback; this is a learning exercise, not a timed exam or professional accreditation.
Lessons and scenarios are original Jatzo material informed by published guidance and research:
- Check Point: Q2 2026 brand phishing report
- Kaspersky: phishing mail sent from a genuine Google notification address
- TrustedSec: device code attacks in Microsoft 365
- Push Security: the rise in device code phishing in 2026
- Huntress: device code phishing compared across Google Cloud and Azure
- Google Workspace: control which third-party and internal apps access your data
- Microsoft Entra: overview of user and admin consent
- Varonis: the Microsoft 365 Direct Send phishing campaign
- BleepingComputer: Google SMTP relay service abused for spoofed mail
- Microsoft: passkeys as the default authentication method in Entra ID
- Google Workspace: allow users to skip passwords at sign-in
- NCSC: phishing scams, how to spot and report them
- NCSC: report a suspicious email
- CISA: implementing phishing-resistant multi-factor authentication
- Cloud Security Alliance: OAuth device code phishing research note
