In this blog post Why MFA Alone Leaves Dangerous Gaps in Microsoft 365 Security we will explain what multi-factor authentication actually protects, where it falls short, and which additional controls reduce the risk of a Microsoft 365 breach.
If your business has enabled MFA, you have taken an important step. But attackers increasingly target the gaps around MFA, including stolen browser sessions, convincing approval requests, unmanaged devices, weak administrator accounts and malicious email rules.
The business risk is simple. A user can complete MFA successfully and an attacker may still gain access to email, files, Teams conversations and sensitive customer information.
What MFA does in plain English
Multi-factor authentication asks a user to provide more than a password. This could be a code, an approval through Microsoft Authenticator, a fingerprint, facial recognition or a physical security key.
Behind the scenes, Microsoft Entra ID, which is the identity and access service behind Microsoft 365, checks these factors before allowing the sign-in. MFA makes a stolen password far less useful because the attacker also needs the second factor.
However, MFA mainly answers one question: did the person complete the required sign-in steps? It does not automatically confirm that the device is secure, the location is reasonable, the user has not been tricked or the activity after sign-in is legitimate.
That is why MFA should be treated as one layer of protection, not the entire security strategy. Our earlier guide on why Microsoft 365 security involves more than turning on MFA provides a useful starting point. The next step is understanding exactly how attackers get around it.
Attackers can steal an authenticated session
A modern phishing page may look almost identical to the Microsoft 365 sign-in screen. The employee enters their password and completes MFA, believing they are signing in normally.
The attacker sits between the employee and Microsoft, passing the information through in real time. Once the sign-in is approved, the attacker steals the session token, which is the digital proof that tells Microsoft the user has already authenticated.
This is sometimes called adversary-in-the-middle phishing. In business terms, it means the attacker may not need the password or another MFA prompt. They can reuse the stolen session to access the employeeโs account.
Reducing this risk requires phishing-resistant sign-in methods such as passkeys, Windows Hello for Business or physical security keys. These methods are tied to the real website and device, making them much harder to relay through a fake sign-in page.
Not every form of MFA provides the same protection
SMS codes and simple push approvals are better than passwords alone, but they remain vulnerable to social engineering. Attackers may repeatedly send approval requests until a tired or distracted employee accepts one.
Number matching improves this process by asking the employee to enter a number shown on the sign-in screen. However, staff can still be manipulated by a convincing phone call, fake support request or phishing page.
A practical approach is to apply stronger authentication first to high-risk people. This includes Microsoft 365 administrators, executives, finance employees, payroll teams and anyone with access to sensitive customer information.
The business outcome is not simply โbetter MFA.โ It is a lower chance that one rushed decision by one employee becomes a company-wide incident.
MFA does not check whether the device is safe
Consider an employee using a personal laptop that has not been patched for months. The device may contain malicious software, have no business-grade security monitoring and be shared with family members.
The employee can still enter the correct password and approve MFA. Without additional access rules, Microsoft 365 may allow that laptop to download company files or synchronise email.
Microsoft Intune, which manages and secures company computers and mobile devices, can check whether a device meets your security requirements. Microsoft Conditional Access can then allow, limit or block access based on the user, device, location, application and level of risk.
For example, staff may be allowed to use Microsoft 365 normally from a compliant company laptop. A personal computer could be limited to browser access and prevented from downloading files.
This is especially important for contractors, remote workers and businesses with bring-your-own-device arrangements. Our guide to the hidden risk of unmanaged devices explains this exposure in more detail.
MFA cannot fix excessive access
If too many people have administrator privileges, MFA does not remove the underlying risk. It simply adds another sign-in step to an account that may already have far more control than it needs.
Administrator accounts should be separate from everyday email accounts. Their use should be restricted, closely monitored and protected with phishing-resistant authentication wherever possible.
Older sign-in methods should also be reviewed and blocked. These legacy methods were designed before modern security controls and can create paths that do not receive the same protection as current sign-ins.
This also matters for the Essential Eight, the Australian Governmentโs cybersecurity framework that many organisations use as a security baseline or contractual requirement. MFA is one of its eight strategies, alongside controls such as restricting administrator privileges, patching systems, controlling applications and maintaining tested backups.
Turning on MFA alone does not mean the organisation has achieved Essential Eight maturity. The control must cover the right users, systems and scenarios, while working alongside the other seven strategies.
MFA does not detect what happens after sign-in
Once an attacker enters an account, they often search email, create forwarding rules, download files or impersonate the user. They may monitor invoice conversations for weeks before changing bank details at the right moment.
MFA cannot identify these actions by itself. Microsoft Defender, Microsoftโs security platform for email, identities, devices and cloud applications, can detect suspicious behaviour and help security teams investigate it.
Sign-in logs, alerts and mailbox rules also need regular review. If an account suddenly signs in from an unusual location, downloads a large volume of information or creates a suspicious forwarding rule, someone must be ready to respond.
Fast detection reduces the time an attacker has to operate. That can be the difference between resetting one account and managing a privacy breach, payment fraud or major business interruption.
A common 200-person business scenario
Imagine a 200-person professional services company. MFA is enabled, so management assumes Microsoft 365 is secure.
A review finds that staff can access SharePoint from unmanaged home computers, several administrators use their privileged accounts for everyday email, SMS remains the main MFA method, and suspicious sign-in alerts are not assigned to anyone.
The solution is not to replace Microsoft 365 or create frustrating restrictions. The company can roll out changes in stages: secure administrator accounts first, block outdated sign-in methods, enrol company devices in Intune, introduce Conditional Access and improve monitoring.
This pattern appears regularly in Microsoft 365 environments. The licences are often already available, but the controls have not been connected or configured around the organisationโs actual risks.
What a stronger Microsoft 365 security model includes
A practical security plan should combine MFA with several supporting controls:
- Conditional Access: checks who is signing in, from where, on which device and under what level of risk.
- Intune device compliance: confirms company devices are encrypted, patched and protected before they reach business data.
- Phishing-resistant authentication: uses passkeys, Windows Hello for Business or security keys for sensitive users and systems.
- Administrator protection: separates privileged accounts and limits administrative access to the people who genuinely need it.
- Microsoft Defender monitoring: detects suspicious email, device, identity and cloud activity.
- Incident response: gives your team a clear process for disabling accounts, revoking sessions and investigating suspicious activity.
These controls should be introduced carefully, using testing and staged deployment. A poorly planned access policy can interrupt legitimate work, while a well-designed one improves security without adding unnecessary prompts.
For a deeper look at how these controls make access decisions together, see how Conditional Access and Intune protect your business. You can also use our Microsoft 365 Conditional Access checklist to identify common policy gaps.
MFA is the starting point, not the finish line
MFA remains essential, but it cannot evaluate every device, stop every phishing technique, correct excessive permissions or investigate suspicious activity. Microsoft 365 security works best when identity, devices, access policies and monitoring operate as one system.
CloudProInc brings more than 20 years of enterprise IT experience to this work. As a Melbourne-based Microsoft Partner and Wiz Security Integrator, we help organisations across Australia and internationally secure Microsoft 365, Azure, Intune, Windows 365 and their broader cloud environment without turning security into a barrier for staff.
If you are not sure whether your MFA setup is providing real protection or simply creating a false sense of security, we are happy to take a practical look at your Microsoft 365 environment โ no strings attached.
Discover more from CPI Consulting
Subscribe to get the latest posts sent to your email.