Credential phishing lands a Microsoft 365 identity
The attacker sends a lure that leads to a look-alike Microsoft sign-in experience. A real employee authenticates, and the attacker captures both the password and, in adversary-in-the-middle style lures, the resulting session — enough to act as that user.
Obtain valid credentials for a real user by capturing them through a convincing sign-in lure.
- Phishing-resistant MFA (FIDO2 / passkeys) rather than SMS or push-only
- Conditional Access requiring compliant or managed devices for M365 sign-in
- User reporting button and fast triage of reported lures
- Entra ID sign-in logs showing new/unusual location, ASN or impossible travel
- Sign-ins from anonymising infrastructure or unfamiliar user agents
- Spike in authentications flagged as risky by identity protection
- A social-engineering assessment measuring click, submit and report rates
- Testing whether MFA method in use can be relayed or bypassed
- Reviewing Conditional Access coverage for gaps and exclusions
The attacker now holds a legitimate identity — every later action looks like a real employee.