Microsoft 365 Phishing Emails
Fake Microsoft sign-in pages are among the most common phishing traps at work. The lures used, how to recognise the real Microsoft sign-in, and how to protect a work account.

If your organization uses Microsoft 365, you are a target for one of the most common phishing lures at work: a fake Microsoft sign-in page. One set of credentials can open email, files, chat and more, so attackers put great effort into making these pages convincing.
Common Microsoft-themed lures
- "Your password expires today." See IT-themed phishing.
- "You have held messages in quarantine."
- "[Name] shared a file with you." See document share phishing.
- "Unusual sign-in activity on your account."
- "Your mailbox is almost full."
- Voicemail or Teams message notifications. See fake voicemail emails.
How to check
- Look at the address bar. Genuine Microsoft sign-ins use Microsoft domains; anything else is not Microsoft. See how to read a URL.
- Notice unexpected prompts. If you are already signed in, being asked again from an email link is suspicious.
- Use bookmarks or apps to reach your mail and files.
- Watch your password manager: it will not autofill on a fake page.
Some fake pages relay your code to the real site. A code prompt does not prove the page is real. Passkeys and security keys resist this. See why some two-step verification can be phished.
If you entered your password
Change it immediately through the real portal, sign out of all sessions, and tell IT. See entered your password on a phishing page.
Got a Microsoft-themed email? Paste it into CyberWatch AI Scan for a free check, and report it to IT.
For more, see how to spot phishing in our complete guide.
Frequently asked questions
How do I know I'm on the real Microsoft sign-in page?
Check the address is a genuine Microsoft domain, such as login.microsoftonline.com or login.live.com. Better still, sign in through your bookmarked portal or app, not from email links.
Why are Microsoft accounts targeted?
Many organizations use Microsoft 365 for email, files and chat, so one login can unlock a lot.
What protects my account best?
Phishing-resistant sign-in such as passkeys or security keys where your organization supports them, plus quick reporting of suspicious emails.
Sources
- Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
- Suspicious email actions, UK National Cyber Security Centre
- Microsoft account recovery form, Microsoft


