Fake Microsoft Login Pages: Training the Eye to Check the URL

Credential phishing is one of the most common ways attackers get into healthcare networks, and the fake Microsoft sign-in page is its most familiar disguise. The page looks right: the logo, the box for your email address, the familiar layout. But it lives at a different web address, and anything you type goes to someone else.

Telling staff to be careful is not enough. People learn to spot counterfeit pages by practicing, in the same way they learn to find a vein or read a chart. This post describes hands-on exercises that build the habit of checking the address before signing in.

What a fake login page looks like

Attackers copy the visual design of the real page, often perfectly. What they cannot copy is the real web address. They try to make the fake address look believable by:

Using a different domain entirely, with a long, confusing address

Adding the company name to a subdomain, such as a real-looking name followed by an unrelated domain

Swapping similar characters, such as a letter "l" for a number "1" or adding a hyphen

Using a link shortener to hide the destination

Hosting the page on a legitimate file-sharing or form service so the link looks harmless

Sending a message with a button labeled "View document" or "Verify account"

The main habit to teach is simple: before typing a password, look at the address bar and confirm the domain is the real one.

How to read a web address

Many people have never learned to read a URL. A short lesson helps a great deal.

The important part is the domain, which is the text right before the first single slash, such as the name immediately before ".com".

Everything to the left of the real domain is a subdomain and can be anything the owner of the domain chooses.

Everything after the first slash is just a path and does not tell you who owns the site.

So an address that begins with a familiar word but ends with an unfamiliar domain is not what it appears to be. Show staff a few fictional examples and have them point to the real domain in each.

Hands-on exercise ideas

Exercise 1: Real or fake?

Print or display several screenshots of sign-in pages, some real and some made up for training. Include the address bar. Ask staff to sort them and explain their reasoning. The discussion matters more than the score.

Exercise 2: Find the domain

Give participants a list of fictional URLs and have them underline the actual domain in each. This builds the reading skill that makes everything else work. Include tricky ones with extra words, hyphens and long subdomains.

Exercise 3: Hover before you click

Show how to hover over a link, or press and hold on a phone, to see where it leads before opening it. Practice with harmless links in a controlled demonstration.

Exercise 4: Go to the front door

Teach staff the safer alternative to clicking a link: open a new browser window, type the address they normally use or use a saved bookmark, and sign in there. If the message was genuine, the item will be waiting.

Exercise 5: Simulated phishing

Work with your IT provider to send simulated phishing emails that lead to a harmless training page. Treat the results as learning, not discipline. Follow up with short coaching for anyone who typed information, and recognize those who reported the message.

Exercise 6: Password manager check

If your staff use a password manager, point out that it often will not fill in a password on a page whose domain does not match the saved one. That refusal is a useful warning sign.

Other clues worth teaching

Unexpected requests to sign in to view a document

Urgent language about expiring passwords or suspended accounts

A sign-in page that appears after clicking a link in a message you did not expect

A page that asks for the multi-factor code or asks you to approve a prompt you did not start

Browsers or security tools showing a warning

Build a response routine

Practice what to do after a mistake. If someone enters a password on a suspicious page:

Tell IT immediately.

Change the password from a trusted device.

Sign out of active sessions.

Review the account for unusual activity, such as new mail rules.

Make it clear that quick reporting is rewarded and not punished.

Technical backups

Training works best alongside technical protections: multi-factor authentication, email filtering, conditional access policies and, for higher-risk roles, phishing-resistant sign-in methods like security keys. These reduce the damage when someone does slip.

Keep practicing

Short, frequent exercises are more effective than one long annual session. UnityCare IT helps healthcare organizations design simple exercises and phishing simulations that fit busy schedules, so checking the address becomes automatic.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172