Skip to content

Free training game

Incident Room

Incident Room is a card game about responding to a phishing attack in Microsoft 365. An attacker has stolen a user's session at a fictional company and wants a supplier invoice paid into their own account. You lead the response team: revoke sessions, reset the password, block the phishing link, check the alerts and stop the payment before the attack track fills.

An incident lasts up to 12 turns on Normal. A short guided training run is offered first, and every response card links to the Microsoft Learn page behind it.

Incident Room 1.0.0

How it teaches

  1. Each response card is a real action, such as revoking sessions in Microsoft Entra ID, blocking a URL in the Tenant Allow/Block List, removing email from mailboxes with Threat Explorer or isolating a device in Microsoft Defender for Endpoint.
  2. The attacker shows their next move and what it needs: a live session, the password, their own MFA method, a hidden inbox rule or a malicious app. Take that away and the move fails, which is how real containment works.
  3. Some alerts are false alarms, so you learn to investigate before you act. Quick fixes such as blocking sign-in work, but they disrupt the business.
  4. After every incident a review shows what went well, what to fix and a strong response, with links to Microsoft Learn.

Read the playbooks the game is built on