Free training game
Incident Room
Incident Room is a card game about responding to a phishing attack in Microsoft 365. An attacker has stolen a user's session at a fictional company and wants a supplier invoice paid into their own account. You lead the response team: revoke sessions, reset the password, block the phishing link, check the alerts and stop the payment before the attack track fills.
An incident lasts up to 12 turns on Normal. A short guided training run is offered first, and every response card links to the Microsoft Learn page behind it.
How it teaches
- Each response card is a real action, such as revoking sessions in Microsoft Entra ID, blocking a URL in the Tenant Allow/Block List, removing email from mailboxes with Threat Explorer or isolating a device in Microsoft Defender for Endpoint.
- The attacker shows their next move and what it needs: a live session, the password, their own MFA method, a hidden inbox rule or a malicious app. Take that away and the move fails, which is how real containment works.
- Some alerts are false alarms, so you learn to investigate before you act. Quick fixes such as blocking sign-in work, but they disrupt the business.
- After every incident a review shows what went well, what to fix and a strong response, with links to Microsoft Learn.