Realistic, nonfunctional training screens show what the user could have seen while the SOC follows the evidence.
TRAINING SIMULATION: all pages are visibly watermarked, inputs are display-only, no credentials are accepted, and no data leaves this file.
What the user may have seen
Behind the scenes
Ask the user now
Do not collect secrets: never ask the user to paste a callback URL, authorization code, token, cookie, or password into Teams, email, or a ticket.
MICROSOFT DEFENDER XDR
MICROSOFT ENTRA
Exposure
Lure visit or unexpected authorization only. Continue investigating.
Suspected token compromise
User confirms transferring the localhost callback. Begin urgent containment.
Confirmed impact
Identity or workload evidence links the session to actual cloud actions.
Current stage assessment
Brand-like sign-in visuals are included solely for internal security-awareness training. They are intentionally noninteractive and prominently marked as a simulation.