About Zero Day: Incident
It's Monday, 07:42, and a finance officer has just signed in to a fake Microsoft 365 page. You work the incident the way you would for real: spot the red flags in the phishing email, revoke sessions and reset MFA in Entra, isolate the laptop in Defender, then explain it all to the Head without making it worse.
Every menu and device action is modelled on the real admin centres, and the steps follow Microsoft's own guidance for adversary-in-the-middle phishing and ransomware. It takes about ten minutes and ends with a scored incident report.
- Related guide: My MFA confession: the setting I missed for 3 years
- Related guide: Intune device action status explained

