0:00–0:10
Recap
0:10–0:30
Lecture
0:30–1:45
Lab 7-C
1:45–1:55
Bonus
1:55–2:00
Debrief
0:00 – 0:10Recap · 10 min

Day 2 review — the threat loop and the human layer gap

0:10 – 0:30Lecture · 20 min

Secure Score and Attack Simulation Training

Attack Simulation uses real M365 mail flow. Simulation emails are delivered to real user mailboxes. Students must target only their own Lakeview Logistics accounts — not each other's tenants. The simulation landing page is completely safe (hosted by Microsoft). Inform students before they start: if they receive what looks like a suspicious email during this lab, it may be their own simulation arriving.
Instructor note: The Secure Score review is genuinely motivating — students see their seven weeks of work reflected as completed score actions. MFA enabled, CA policies on, device compliance configured, Safe Attachments active — all show as positive contributions. Frame this explicitly: "Every lab you completed is worth points in this score." Then identify 2–3 remaining gaps together before students pick their own three to implement.
0:30 – 1:45Guided lab · 75 min

Lab 7-C: Secure Score analysis and Attack Simulation Training

Students review and document their Secure Score, identify completed and incomplete actions from Weeks 1–7, implement three score-improving actions, launch a Credential Harvest simulation against their Lakeview Logistics users, and review the simulation results report.

Instructor note: Step 5 — clicking the simulation link — is the most viscerally effective moment of the week. Students who click through the credential harvest page and then see the "this was a simulation" page understand immediately why users fall for phishing. The Microsoft-hosted landing pages are high quality replicas of real Microsoft login pages. Make sure students understand before clicking that no credentials are actually captured by any external party — the click data goes only to the Attack Simulation Training reports in their own tenant.
1:45 – 1:55Bonus · 10 min

⭐ Bonus: Custom simulation payload and training campaign

⭐ Bonus A — Create a custom simulation payload
  • Navigate to Attack simulation training → Simulation content library → Payloads → + Create payload
  • Technique: Credential Harvest. Name: LL — Internal IT Notice. Create a payload that impersonates an internal IT notification from Sarah Chen — "Your M365 password expires in 24 hours. Click here to reset it."
  • Configure the sender to appear as sarah.chen@[yoursubdomain]. Use the phishing indicators panel to rate the complexity of your payload
  • Save the payload and note its predicted click rate. In your Lab Journal: what specific elements of your payload make it convincing, and what are the most detectable signs a careful user might notice?
⭐ Bonus B — Assign remediation training
  • Navigate to Attack simulation training → Training → + Assign training
  • Assign the Phishing training module to all users who clicked in the simulation (or to all users regardless, for this lab)
  • Set a due date of 14 days. Review the training content — what does the module teach users to look for?
  • Lab Journal: in a real organisation, should all users receive the same phishing awareness training, or should training be targeted based on simulation results? What are the arguments for each approach?
1:55 – 2:00Debrief · 5 min

Reflection & preview

Learning outcomes — by end of Day 3, students can…

Read Secure ScoreInterpret the score, categories, and recommended actions list
Map actions to labsIdentify which course labs contributed to completed Secure Score actions
Improve the scoreImplement at least three new recommended actions and verify the score increase
Launch a simulationConfigure and launch a Credential Harvest simulation targeting all Lakeview Logistics users
Experience phishingClick through a simulation and observe the training landing page from the user's perspective
Read simulation resultsInterpret the delivery, click, credential submission, and training assignment metrics

What you need ready

security.microsoft.com accessible All 10 Lakeview Logistics users have mailboxes and credentials known Defender for M365 Plan 2 active (from Day 1) Attack Simulation Training licence confirmed (part of E5 Security)
Day 4 →Week 7 Overview