Multi-factor authentication is one of the most important security controls a business can enable in Microsoft 365.

It makes stolen passwords significantly less useful because a person signing in must provide an additional form of verification. For many businesses, enabling MFA is one of the fastest and most valuable security improvements they can make.

But MFA is not a complete Microsoft 365 security strategy.

Attackers continue to develop techniques that target users, devices, applications and active sign-in sessions. A business can have MFA enabled and still experience mailbox compromise, data exposure or unauthorised access.

The practical answer is therefore:

MFA is essential, but it needs to operate as part of a wider set of security controls.

Key takeaways

MFA should be enabled for every user, particularly administrators and people with access to sensitive information.

MFA should be enabled for every user, particularly administrators and people with access to sensitive information.

MFA should be enabled for every user, particularly administrators and people with access to sensitive information.

Conditional Access can help determine when, where and how users are permitted to sign in.

Microsoft 365 security should be reviewed regularly as the organisation, technology and threat environment change.

Why MFA remains important

Passwords are regularly exposed through phishing, password reuse, malware and data breaches involving unrelated services.

If an account relies only on a password, obtaining that password may be enough for an attacker to sign in.

MFA introduces another verification requirement. Depending on the configuration, this might involve an authenticator application, a device-bound passkey, biometric verification, a hardware security key or a one-time code.

This additional step makes many common account takeover attempts more difficult. It is why MFA should be regarded as a minimum requirement for business email, remote access, financial systems and other important cloud services.

However, enabling MFA does not make every sign-in trustworthy.

How an attacker may still get around MFA

1

MFA fatigue and social engineering

Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.

2

Stolen sign-in sessions

After a successful authentication, Microsoft 365 uses tokens to maintain the user’s session.

Sophisticated phishing techniques can attempt to intercept credentials and session information while the user is signing in. If an attacker successfully steals a valid session token, they may be able to reuse the authenticated session without completing a new MFA challenge.

This is one reason MFA should be combined with device protection, Conditional Access, session controls and effective monitoring.

3

Compromised or unmanaged devices

MFA helps confirm the person attempting to sign in, but it does not prove that the device itself is safe.

A device affected by malware may expose browser sessions, documents, email or saved credentials. An unmanaged personal computer may also lack appropriate updates, encryption, endpoint protection or screen-lock settings.

Businesses therefore need to consider both user identity and device condition.

4

Malicious application consent

Users can sometimes be persuaded to approve an application that requests access to their Microsoft 365 information.

Instead of stealing the password directly, the application may seek permission to read email, files, contacts or other organisational data. Depending on the permissions granted, the application may retain access until its consent is identified and revoked.

Application consent settings and approved application processes should form part of the Microsoft 365 security review.

5

Legacy authentication and policy exceptions

Older authentication protocols may not support modern MFA controls.

Microsoft recommends blocking legacy authentication wherever possible. Any exclusions from security policies should be documented, limited and reviewed because an unnecessary exception can become a path around an otherwise strong configuration.

6

Compromised mailboxes and hidden rules

A successful account compromise may be followed by mailbox forwarding, inbox rules, unusual out-of-office settings or other changes designed to conceal activity.

MFA cannot remove a malicious rule that already exists. The organisation also needs alerts, audit information and an established investigation process.

7

Excessive administrator access

Administrator accounts can make significant changes across Microsoft 365.

If too many people hold permanent administrative roles - or administrators use the same account for email and privileged work - the potential effect of a compromise increases.

Administrative access should be separated, restricted and reviewed regularly.

What stronger Microsoft 365 protection looks like

A more complete security approach combines several layers.

1

Require MFA for all users

Start by ensuring MFA applies consistently. Pay particular attention to administrators, finance staff, executives and anyone with access to sensitive business information.

Do not assume an account is covered simply because some users have registered an authentication method.

2

Move towards phishing-resistant authentication

Device-bound passkeys, Windows Hello for Business and compatible hardware security keys can provide greater resistance to phishing than passwords combined with one-time codes.

The appropriate method depends on licensing, device management, user roles and operational requirements. Privileged accounts are a sensible place to begin.

3

Use Conditional Access

Conditional Access can evaluate signals such as the user, application, device, location and authentication method before granting access.

Depending on the business requirements and available licensing, policies may be used to:

  • require MFA;

  • block legacy authentication;

  • require stronger authentication for administrators;

  • restrict access from unmanaged devices;

  • protect sensitive applications;

  • block access in defined high-risk circumstances; and

  • establish controlled emergency-access arrangements.

Policies should be introduced carefully. Use report-only testing where available, maintain emergency access accounts and confirm that legitimate business workflows will continue to operate.

4

Protect and manage devices

Business devices should receive security updates, endpoint protection and consistent configuration.

Where appropriate, device management can help the organisation apply encryption, compliance and access requirements. Lost, retired and replaced devices should also be removed from the active environment.

5

Review email protection

Microsoft 365 security also needs controls addressing phishing, malicious attachments, unsafe links, impersonation and unusual forwarding activity.

The exact capabilities available depend on the organisation’s Microsoft 365 licensing.

6

Control application access

Review enterprise applications and user consent settings. Users should understand that approving an application can grant continuing access to business information.

Applications that are unused, unrecognised or excessively privileged should be investigated.

7

Monitor sign-ins and configuration changes

Security controls are more effective when the business can recognise unusual behaviour.

Relevant monitoring may include:

  • unfamiliar sign-in locations;

  • unexpected administrator changes;

  • suspicious mailbox rules;

  • unusual forwarding settings;

  • newly approved applications;

  • repeated MFA prompts;

  • disabled security controls; and

  • activity involving dormant accounts.

Alerts still require ownership. The business should know who reviews them and what happens when something appears suspicious.

An example from an OmekaTech engagement

PRACTICAL EXAMPLE

In one anonymised engagement, a business had lost access to its Microsoft 365 environment and could no longer use email normally.

The work involved investigating the tenant, recovering access and improving the configuration. The organisation moved from Microsoft 365 Business Basic to Business Premium, introduced Conditional Access and completed a broader security uplift.

Microsoft Secure Score increased from approximately 25% to 65% during the engagement.

That improvement helped demonstrate that more recommended controls had been implemented. It did not mean that every risk had disappeared. Secure Score is a useful measurement and planning tool, but it should not be treated as a guarantee that an incident cannot occur.

The engagement illustrates the wider point: licensing, configuration, device protection, administrative access and monitoring all matter. MFA is only one part of the security position.

Client details have been withheld to protect confidentiality. Results vary according to the environment, licensing, starting position and scope of work.

Questions leadership should ask

  1. Is MFA enforced for every active user?
  2. Which MFA methods are permitted?
  3. Are stronger authentication methods required for administrators?
  4. Are legacy authentication methods blocked?
  5. How many accounts hold administrator roles?
  6. Are business devices managed and protected?
  7. Who reviews security alerts and suspicious sign-ins?
  8. Are mailbox forwarding and application consent reviewed?
  9. Is there a documented response process for a compromised account?
  10. When was the Microsoft 365 security configuration last assessed?

Unclear answers indicate that a structured review may be appropriate.

Practical next actions

For many growing businesses, a sensible initial sequence is:

01

Confirm that MFA is enforced for all users.

02

Review the authentication methods currently permitted.

03

Separate routine and administrative accounts.

04

Identify and block legacy authentication.

05

Review Conditional Access policies and exclusions.

06

Confirm device management and endpoint protection coverage.

07

Examine mailbox forwarding, inbox rules and application consent.

08

Configure relevant monitoring and alerts.

09

Document the account-compromise response process.

10

Review progress against business risks rather than relying on a score alone.

MFA is the starting point - not the finish line

MFA remains one of the most valuable protections available to a business using Microsoft 365.

It should be enabled consistently and strengthened over time. But it cannot protect the organisation from every malicious application, infected device, stolen session, configuration weakness or incident-response failure.

Effective Microsoft 365 security uses multiple controls to reduce the chance of compromise, limit the potential impact and help the business respond quickly when something goes wrong.

Know where your Microsoft 365 environment stands

OmekaTech helps Brisbane businesses review Microsoft 365 identity, email, devices, administrative access and security configuration.

Start with an Executive Technology and Security Assessment to identify material risks and establish practical priorities.