logo

Defending the Gates of Microsoft Azure With MFA

ID: 3f52c417-9899-5d59-b2ab-c4a0973af9b9

STIX ID: report--3f52c417-9899-5d59-b2ab-c4a0973af9b9

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This blog post outlines common Azure tenant attack techniques (OSINT user enumeration, OneDrive/OneDrive-user enumeration, password spraying, and MFA bypass via unregistered registration or push-notification fatigue) from an attacker’s perspective and maps those techniques to mitigations: securing security information registration with Conditional Access and trusted IPs, requiring MFA for admins/users, enabling number matching, blocking legacy authentication, and monitoring MFA registration/reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.