Skip to content
JatzoOnline Security
← All modulesIllustration for Protecting your work account

Workplace MODULE

Protecting your work account

The account is the real target. Learn what your provider actually does.

Your work account is the thing attackers want, whether your organisation signs in with Microsoft 365 or with Google Workspace. This module covers the four ways such an account is actually taken, including the attacks that keep working when multi-factor authentication is switched on.

  • Tell a genuine notification from your provider apart from an imitation of one.
  • Recognise the sign-in, code and permission requests that defeat multi-factor authentication.
  • Verify and report a suspect message without needing a technical background.

Your learning path

01The name worth borrowingRecognise what a genuine message from your provider does, and what it rarely does.Locked02The sign-in page that keeps your passwordUnderstand why a perfect copy of a sign-in page defeats both a strong password and a code.Locked03The code you were asked to typeRecognise device code phishing, where every page you see genuinely belongs to the provider.Locked04Permission is not the same as a passwordRecognise a consent request that hands over access without ever asking for credentials.Locked05When it appears to come from insideApply the same checks when a message appears to come from a colleague or from your own organisation.Locked06Check it, report it, recover from itAct confidently after a suspicious message, including when you have already clicked.Locked

Put your decisions into practice.

Complete each lesson’s scenario, then take eight new questions. A score of at least 80% earns a personal completion record. Retry with feedback; this is a learning exercise, not a timed exam or professional accreditation.

Lessons and scenarios are original Jatzo material informed by published guidance and research: