0:00–0:10
Recap
0:10–0:30
Lecture
0:30–1:45
Lab 7-C
1:45–1:55
Bonus
1:55–2:00
Debrief
0:00 – 0:10Recap · 10 min
Day 2 review — the threat loop and the human layer gap
- Ask: "WIN-CLIENT-01 is onboarded to Defender for Endpoint. The risk-level compliance gate is set. A sophisticated attacker sends a spear-phishing email to Sarah Chen. Safe Attachments quarantines the attachment. But Sarah calls the attacker back using a phone number in the email body, and over the phone gives them her M365 password and MFA code. Which of this week's controls helped?" — none of them. Technology controls don't stop social engineering. The human layer is the last gap.
- Ask: "How would you measure how vulnerable Lakeview Logistics users are to phishing right now, without waiting for a real attack?" — attack simulation. You send a controlled phishing email and measure who clicks.
- Frame: Day 3 has two parts. First — Secure Score, which gives a single number for the entire tenant's security posture based on all configurations. Students will see their Week 1–7 work reflected in the score. Second — Attack Simulation Training, which tests the human layer and generates training for users who click simulated phishing links.
0:10 – 0:30Lecture · 20 min
Secure Score and Attack Simulation Training
- Microsoft Secure Score — a numeric measure of an organisation's security posture, ranging from 0 to a tenant-specific maximum. Each security action (enabling MFA, requiring device compliance, configuring Safe Attachments etc.) contributes a defined number of points. The score is not a grade — it measures coverage of Microsoft's recommended security controls relative to what your licence enables. A score of 65% means 65% of available recommended actions have been implemented.
- What Secure Score evaluates — three categories: Identity (MFA, CA policies, Entra ID settings), Device (Intune compliance, Defender for Endpoint onboarding, update policies), and Apps (Safe Attachments, Safe Links, anti-phishing, DLP). Each recommended action shows: the number of points it's worth, the current status (completed/not completed/not applicable), and a description of what to configure. Students should recognise their Week 1–7 work in the completed actions.
- Secure Score is a management tool, not a security guarantee — a score of 100% does not mean you can't be breached. It means you have implemented all of Microsoft's recommended controls. Real-world attackers find ways around controls. Secure Score measures control coverage, not attack resistance. It is useful for tracking posture over time, benchmarking against similar organisations, and prioritising which controls to implement next.
- Attack Simulation Training — a built-in tool in Defender for M365 Plan 2 that sends controlled phishing simulations to real users using real M365 mail flow. No real credentials are captured — the landing page is a Microsoft-hosted training page. Simulations generate reports showing: who received the email, who clicked the link, who submitted credentials on the landing page, and who reported the email as phishing. Users who click are automatically assigned remediation training modules.
- Simulation types — five phishing techniques: Credential Harvest (fake login page), Malware Attachment (simulated malicious attachment), Link in Attachment (PDF with a link), Drive-by URL (visiting a URL that auto-downloads), OAuth Consent Grant (fake app permission request). Today's lab uses Credential Harvest — the most common real-world phishing technique and the most visually impactful for students to experience from both sides.
Attack Simulation uses real M365 mail flow. Simulation emails are delivered to real user mailboxes. Students must target only their own Lakeview Logistics accounts — not each other's tenants. The simulation landing page is completely safe (hosted by Microsoft). Inform students before they start: if they receive what looks like a suspicious email during this lab, it may be their own simulation arriving.
Instructor note: The Secure Score review is genuinely motivating — students see their seven weeks of work reflected as completed score actions. MFA enabled, CA policies on, device compliance configured, Safe Attachments active — all show as positive contributions. Frame this explicitly: "Every lab you completed is worth points in this score." Then identify 2–3 remaining gaps together before students pick their own three to implement.
0:30 – 1:45Guided lab · 75 min
Lab 7-C: Secure Score analysis and Attack Simulation Training
Students review and document their Secure Score, identify completed and incomplete actions from Weeks 1–7, implement three score-improving actions, launch a Credential Harvest simulation against their Lakeview Logistics users, and review the simulation results report.
- Part 1 — Secure Score (30 min)
- Step 1 — Record baseline Secure Score (5 min)
Navigate to security.microsoft.com → Secure Score (left nav, under Exposure management or directly in left sidebar).
Record: current score, maximum possible score, and percentage. Also record the breakdown by category (Identity, Device, Apps).
- Step 2 — Map completed actions to course labs (10 min)
Navigate to Recommended actions tab. Filter by Status = Completed. For each completed action, identify which lab implemented it. Record in the mapping table in the lab handout.
Then filter by Status = To address. Review the top 10 not-yet-completed actions — note the point value of each and the category.
- Step 3 — Implement three score-improving actions (15 min)
From the "To address" list, choose three actions you can implement now. Good candidates (not already covered in earlier labs):
· Enable self-service password reset (SSPR) — Entra ID → Password reset → Properties → Enable for All users
· Enable Entra ID Identity Protection risk-based sign-in policy — Entra ID → Identity Protection → Sign-in risk policy → Risk level: Medium and above → Block access
· Turn on unified audit log — Purview portal → Audit → Start recording user and admin activity (if not already on)
· Set outbound spam policy notification — security.microsoft.com → Anti-spam → outbound policy → add admin notification email
Implement each chosen action, verify it shows as Completed in Secure Score, and record the point increase.
- Part 2 — Attack Simulation Training (45 min)
- Step 4 — Launch a Credential Harvest simulation (20 min)
Navigate to security.microsoft.com → Email & collaboration → Attack simulation training → Simulations → + Launch simulation.
· Technique: Credential Harvest
· Name: LL Phishing Simulation 01
· Payload: select 2 Failed Messages or Account Suspended (Microsoft-provided templates — choose one that looks realistic)
· Target users: add all 10 Lakeview Logistics users (Sarah Chen, Dev Sharma, Marcus Webb, Priya Nair, Tom Bellamy, Diane Rousseau, Kevin Park, Leila Farrokhzad, James Okafor, Aisha Mwangi)
· Launch details: Start immediately
· Training assignment: Auto-assign training to users who click
· End user notifications: Microsoft default notification
Launch the simulation.
- Step 5 — Experience the simulation email (10 min)
Sign into the mailbox of one of the Lakeview Logistics users (e.g. priya.nair@[yoursubdomain]) using the user's credentials.
Check the inbox — the simulation email should arrive within a few minutes. Read it critically: what makes it convincing? What are the tell-tale signs it might be suspicious?
Click the link in the simulation email. You will land on a Microsoft-hosted credential harvest page. Enter fake credentials (don't use real ones — but note the page looks like a real login). Submit.
You will then see the training landing page explaining this was a simulation and what to look for in real phishing emails.
Return to your admin account.
- Step 6 — Review simulation results (15 min)
Navigate back to Attack simulation training → Simulations → LL Phishing Simulation 01. Click the simulation to open the results report.
Note: results take time to populate — you may only see data for the one user who clicked (from Step 5). Full results for all users may take 15–30 minutes to appear.
Review: users targeted, delivery rate, click rate, credential submission rate, reported phishing rate, training assigned.
Record all metrics in the lab handout table.
Instructor note: Step 5 — clicking the simulation link — is the most viscerally effective moment of the week. Students who click through the credential harvest page and then see the "this was a simulation" page understand immediately why users fall for phishing. The Microsoft-hosted landing pages are high quality replicas of real Microsoft login pages. Make sure students understand before clicking that no credentials are actually captured by any external party — the click data goes only to the Attack Simulation Training reports in their own tenant.
1:45 – 1:55Bonus · 10 min
⭐ Bonus: Custom simulation payload and training campaign
⭐ Bonus A — Create a custom simulation payload
- Navigate to Attack simulation training → Simulation content library → Payloads → + Create payload
- Technique: Credential Harvest. Name: LL — Internal IT Notice. Create a payload that impersonates an internal IT notification from Sarah Chen — "Your M365 password expires in 24 hours. Click here to reset it."
- Configure the sender to appear as sarah.chen@[yoursubdomain]. Use the phishing indicators panel to rate the complexity of your payload
- Save the payload and note its predicted click rate. In your Lab Journal: what specific elements of your payload make it convincing, and what are the most detectable signs a careful user might notice?
⭐ Bonus B — Assign remediation training
- Navigate to Attack simulation training → Training → + Assign training
- Assign the Phishing training module to all users who clicked in the simulation (or to all users regardless, for this lab)
- Set a due date of 14 days. Review the training content — what does the module teach users to look for?
- Lab Journal: in a real organisation, should all users receive the same phishing awareness training, or should training be targeted based on simulation results? What are the arguments for each approach?
1:55 – 2:00Debrief · 5 min
Reflection & preview
- Ask: "Your Secure Score went up after implementing the three actions. Does that mean Lakeview Logistics is now more secure than yesterday?" — yes, in the sense that more controls are in place. No, in the sense that the score measures control coverage, not actual threat resistance. A breach can still happen even at 100%.
- Ask: "A user clicked the simulation link. Attack Simulation Training automatically assigned them training. That's automated. What is something the simulation cannot do automatically that still requires human judgment?" — investigate whether any real phishing emails arrived around the same time, follow up with the user to understand why they clicked, assess whether the job role suggests higher risk that needs targeted training.
- Preview Day 4: the human layer is tested. Day 4 moves to the data layer — DLP policies that prevent sensitive data from leaving the organisation, and endpoint DLP that blocks USB transfers and unauthorised cloud uploads. The financial data (credit card numbers, bank account numbers) that Priya Nair's Finance team works with every day is the target.
Learning outcomes — by end of Day 3, students can…
Read Secure ScoreInterpret the score, categories, and recommended actions list
Map actions to labsIdentify which course labs contributed to completed Secure Score actions
Improve the scoreImplement at least three new recommended actions and verify the score increase
Launch a simulationConfigure and launch a Credential Harvest simulation targeting all Lakeview Logistics users
Experience phishingClick through a simulation and observe the training landing page from the user's perspective
Read simulation resultsInterpret the delivery, click, credential submission, and training assignment metrics
What you need ready
security.microsoft.com accessible
All 10 Lakeview Logistics users have mailboxes and credentials known
Defender for M365 Plan 2 active (from Day 1)
Attack Simulation Training licence confirmed (part of E5 Security)