A valid password is already held
The attacker starts with a valid password obtained from a prior breach or phishing, meaning the only remaining barrier is the multi-factor prompt.
Have a working password so only the second factor stands in the way.
- Breached-password screening and forced resets
- Phishing-resistant MFA that cannot be approved by a simple tap
- Conditional Access limiting where sign-in is even attempted
- Sign-in attempts with correct password from unusual locations
- Credential matches against known-breached lists
- Repeated authentication attempts for one account
- Assess exposure of reused/breached passwords
- Review whether MFA method resists prompt approval
- Test Conditional Access coverage
Only the second factor now protects the account.