Exploiting MFA Inconsistencies on Microsoft Services
ID: 8e498e02-c96a-5354-bc52-1abf7988a4f1
STIX ID: report--8e498e02-c96a-5354-bc52-1abf7988a4f1
Feed Name: Black Hills Infosec Blog
This report examines inconsistent MFA enforcement across Microsoft 365/Azure caused by Security Defaults vs. Conditional Access choices and legacy protocols, and introduces the PowerShell tool **MFASweep** to test multiple endpoints (Graph, Azure Service Management, EWS, web portals—including mobile user-agent scenarios—and ActiveSync/ADFS) for single-factor gaps, providing actionable guidance for operators and defenders to validate and harden MFA coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
