See what is exposed, wasted, or ready for AI. Start your Technology Readiness Review.

How Attackers Walk Past Multi-Factor — and the Simple Steps That Stop Them

Microsoft 365 Security

But we turned MFA on.

A business owner said that to us recently, half a question and half a protest. Someone had gotten into a company mailbox, changed a payment detail on an invoice, and quietly forwarded a week of messages to an outside address.

The owner had done the responsible thing months earlier and switched on multi-factor authentication for everyone.

So how did this happen?

It is a fair question, and the answer is more reassuring than it first sounds. Multi-factor authentication still works. What changed is the way attackers get around it.

What is actually happening

The newest Microsoft 365 phishing does not always try to steal your password anymore. It steals your session: the digital “wristband” your computer gets after you have already logged in and passed your MFA prompt. Security teams often describe this as token theft, session cookie theft, or adversary-in-the-middle phishing.

Here is the plain version. You click a link in a convincing email and land on a page that looks like a Microsoft sign-in screen, or you are asked to enter a device code into a real Microsoft login page. You type your password or approve the sign-in. Everything feels normal. But the attacker is sitting in the middle, passing the login along and capturing the access token on the way through.

From there, the attacker may be able to open email, Teams, OneDrive, and SharePoint without needing the password again or triggering a second MFA prompt.

This is not theoretical.

In May 2026, the FBI warned that the Kali365 phishing-as-a-service platform was being used to capture Microsoft 365 OAuth tokens and bypass MFA protections.

The money trail is real.

The FBI describes business email compromise as one of the most financially damaging online crimes, often involving fake invoices, payment changes, and trusted-looking requests.

Wouldn’t it be better if sign-ins were aware?

MFA was step one, and it was the right step. But wouldn’t it be better if your sign-ins did not only check who is logging in, but also where they are logging in from, what device they are using, and whether a stolen session should be trusted somewhere else?

That is the shift: from “we have MFA” to “our sign-ins are aware.” The good news is that many of the tools to do this are already sitting inside Microsoft 365. They usually just need to be turned on, tuned, and monitored.

The fix, in plain language

A handful of practical moves close much of this gap, and none of them require ripping everything out.

01

Turn off legacy sign-in methods.

Old protocols and older authentication patterns can leave side doors open. Attackers look for those paths because they are easier to abuse and harder for users to notice.

02

Add sign-in awareness.

Conditional Access can flag or block logins from unexpected locations, risky sessions, or unmanaged devices. A stolen token from an unusual place should not simply sail through.

03

Move toward phishing-resistant sign-in.

Passkeys, FIDO2 security keys, and device-bound authentication are much harder to trick than a code someone can type into a page.

04

Watch for tell-tale mailbox rules.

Auto-forwarding, hidden inbox rules, and unusual mailbox activity are often how email break-ins stay quiet. Alerting on them turns a silent problem into an early warning.

Why it is worth doing now

The payoff is concrete. It reduces risk because the single most expensive incident many smaller organizations face is exactly this kind of email break-in. Closing the session-theft gap takes one of the most common paths off the table.

It can also help you get more value from the Microsoft 365 you already pay for. Many of the protections above are included in common Microsoft 365 plans, but included does not mean configured. This is often less about buying something new and more about using what is already there.

And it buys back time and trust. No scramble to explain a fraudulent invoice to a customer. No week lost to cleanup. No uncomfortable call that begins, “We think someone may have been in our mailbox.”

Where to start

You do not have to figure out which settings matter on your own. A Security Score Snapshot gives you a plain-English view of where your Microsoft 365 sign-in and email security gaps are, which included protections matter most, and what should be switched on first.

Wouldn’t it be better to know where you stand before someone else finds out for you?

Grab your Security Score Snapshot.

We will walk you through what your Microsoft 365 security posture means, where session-theft gaps may exist, and which included protections are worth switching on first.

Covenant Technology Solutions | Microsoft-first. Security-first. Human.

Scroll to Top