Multi-factor authentication (MFA) remains one of the most important security controls a business can implement. But modern Microsoft 365 phishing attacks are becoming more sophisticated — and some can steal authenticated sessions even after a user completes conventional MFA.
For Australian businesses relying on Microsoft 365 for email, documents, collaboration and day-to-day operations, that distinction matters.
The issue is not that MFA is useless. Far from it. The Australian Cyber Security Centre continues to recommend MFA as one of the fundamental measures businesses should implement to protect important accounts.
The challenge is that cybercriminals are increasingly using techniques designed to work around weaker forms of MFA rather than simply trying to steal a password.
One important example is adversary-in-the-middle phishing, commonly abbreviated to AiTM.
How Can a Microsoft 365 Phishing Attack Bypass MFA?
A conventional phishing attack typically tries to trick a user into entering their username and password into a fraudulent website.
An AiTM attack goes further.
Instead of simply displaying a fake login form, the attacker places malicious infrastructure between the victim and the legitimate Microsoft authentication service.
The victim may see what appears to be a normal Microsoft 365 login process. They enter their username and password and may even successfully complete an MFA challenge.
While this happens, the attack infrastructure can relay the authentication process and attempt to capture the authenticated session token or session cookie.
Microsoft has documented this technique and explains that stolen session cookies can allow an attacker to impersonate the authenticated user without requiring the attacker to complete the authentication process again.
Learn more about Microsoft’s research into AiTM token compromise .
This Does Not Mean MFA Has Failed
This point is important.
Businesses should not respond to MFA-bypass attacks by disabling MFA.
MFA still provides substantially stronger account protection than passwords alone and should remain enabled wherever possible.
The lesson from modern phishing campaigns is that businesses should begin moving important accounts towards phishing-resistant authentication methods and combine authentication with other Microsoft 365 security controls.
SwiftTech’s Essential Eight cybersecurity services help businesses implement stronger identity, access, backup and system-security controls based on guidance from Australia’s cyber security authorities.
Why Microsoft 365 Accounts Are Attractive Targets
A compromised Microsoft 365 account can provide considerably more value to an attacker than access to a single email inbox.
Depending on the user’s permissions and your Microsoft 365 configuration, an account may provide access to:
- Outlook email and historical conversations
- Microsoft Teams communications
- OneDrive files
- SharePoint documents
- Calendars and contacts
- Customer or supplier information
- Financial conversations and invoices
- Internal business information
An attacker who gains access to email may also use that account to conduct business email compromise (BEC).
Microsoft 365 Phishing Can Become a Financial Risk
Business email compromise is particularly dangerous because an attacker may be communicating from a legitimate compromised account rather than simply pretending to own it.
Imagine an attacker gaining access to the mailbox of somebody involved in accounts or purchasing.
They may study previous emails, learn which suppliers the company works with and understand how payments are normally authorised.
The attacker can then wait for a genuine invoice discussion and attempt to insert fraudulent banking details into the conversation.
The Australian Cyber Security Centre warns that business email compromise can involve compromised employee or supplier accounts and may be used to steal money, goods or sensitive business information.
Read the Australian Cyber Security Centre’s guidance on preventing business email compromise .
This is why email security should be viewed as both an IT security control and a financial control.
What Should Australian Businesses Do?
There is no single setting that eliminates every Microsoft 365 security risk. A stronger approach uses multiple layers of protection.
1. Keep MFA Enabled
First, continue using MFA.
The Australian Cyber Security Centre recommends enabling MFA wherever possible, particularly for important accounts such as email, banking and cloud document storage.
Businesses that have not yet implemented MFA across Microsoft 365 should treat this as an important security priority.
SwiftTech provides broader cybersecurity and IT security solutions for businesses that need assistance reviewing or strengthening their existing protection.
2. Move Important Accounts to Phishing-Resistant MFA
Not every authentication method provides the same level of protection against phishing.
For high-value and administrative accounts, organisations should consider moving towards phishing-resistant methods such as:
- FIDO2 security keys
- Passkeys
- Windows Hello for Business where appropriate
- Microsoft Entra certificate-based authentication where appropriate
Microsoft recommends phishing-resistant MFA for privileged Microsoft Entra administrator roles.
View Microsoft’s phishing-resistant MFA guidance .
3. Consider Passkeys
Passkeys can help reduce reliance on passwords and make conventional credential-phishing attacks significantly harder to execute successfully.
Australia’s Cyber Security Centre describes passkeys as a faster and more secure way to log in and notes that they can help prevent criminals from stealing passwords through scams or fake websites.
Read the Australian Cyber Security Centre’s passkey guidance .
4. Review Microsoft Entra Conditional Access
Microsoft 365 security should not rely only on a password followed by an MFA request.
Microsoft Entra Conditional Access allows businesses to apply security decisions using additional information such as:
- User or administrator role
- Authentication strength
- Application being accessed
- Device state
- Location and other sign-in conditions
Microsoft recommends testing new Conditional Access policies using report-only mode before fully enforcing them.
This is important because improperly configured access policies can accidentally prevent legitimate employees or administrators from accessing critical services.
5. Protect Administrator Accounts First
Administrator accounts represent particularly valuable targets because they can provide extensive control over an organisation’s Microsoft 365 environment.
Review who currently has administrative permissions and remove privileges that are no longer required.
Administrator accounts should receive stronger authentication protection than ordinary accounts wherever possible.
This approach also aligns with the access-control and privilege-management principles used within SwiftTech’s Essential Eight implementation services.
6. Train Staff to Recognise Modern Phishing
Cybersecurity awareness training needs to move beyond simply telling employees to look for spelling mistakes.
Modern phishing messages can appear polished, professional and convincing.
Employees should be cautious when an unexpected message asks them to:
- Sign in to Microsoft 365 again
- Open an unexpected document
- Listen to a voicemail through an unfamiliar link
- Approve an MFA request they did not initiate
- Enter a one-time authentication code
- Scan an unexpected QR code
- Change supplier or payment information urgently
If a message appears suspicious, staff should independently contact the person or organisation using trusted contact information rather than phone numbers or links contained in the suspicious message.
7. Protect Your Payment Processes
Technical security controls should be supported by good business procedures.
A request received through email alone should not normally be sufficient to authorise a change to supplier banking details.
Businesses should establish an independent verification process for:
- New supplier bank accounts
- Changes to existing bank details
- Unusually large payments
- Urgent or unusual financial requests
Verification through a second trusted communication channel can prevent a compromised mailbox from immediately becoming a financial loss.
8. Monitor Microsoft 365 for Suspicious Activity
Businesses should have visibility into their Microsoft 365 environment so suspicious activity can be identified quickly.
Depending on your environment, useful indicators can include:
- Unexpected sign-ins
- Unusual geographic locations
- Suspicious authentication activity
- New email-forwarding rules
- Changes to authentication methods
- Unexpected administrator changes
- Unusual mailbox activity
A broader review of your systems, endpoints and network infrastructure and security can also identify weaknesses outside Microsoft 365 that may contribute to an attack.
What Should You Do If a Microsoft 365 Account Is Compromised?
If you believe an employee has entered credentials into a phishing page or an account may have been compromised, treat it as a cybersecurity incident.
Changing the password alone may not be sufficient when an authenticated session token has been stolen.
Your response may need to include:
- Resetting the affected user’s credentials
- Revoking active sessions and authentication tokens
- Reviewing sign-in logs
- Checking registered MFA methods
- Reviewing mailbox forwarding and inbox rules
- Checking delegated mailbox permissions
- Reviewing administrator-role changes
- Checking messages sent from the compromised account
- Contacting affected customers or suppliers where appropriate
- Contacting your financial institution immediately if payment information may have been affected
The Australian Cyber Security Centre provides specific guidance for organisations recovering from business email compromise.
View ACSC business email compromise recovery guidance .
Don’t Forget Backup and Recovery
Identity and email security are only part of a resilient cybersecurity strategy.
If a cyber incident affects important business information or expands into ransomware or data destruction, reliable backups can be critical to recovery.
SwiftTech’s data protection, backup and recovery solutions are designed to help organisations protect critical information and maintain business continuity when incidents occur.
MFA Is Still Essential — But Businesses Need to Go Further
The lesson from modern Microsoft 365 phishing attacks is not that MFA has failed.
The lesson is that cybercriminal techniques continue to evolve.
Passwords alone became insufficient, so organisations adopted MFA. Attackers then developed techniques capable of manipulating users and stealing authenticated sessions.
Businesses should therefore continue strengthening their security by combining:
- Multi-factor authentication
- Phishing-resistant authentication
- Conditional Access
- Administrator account protection
- User awareness training
- Monitoring and logging
- Secure payment procedures
- Reliable backup and recovery
For many organisations, Microsoft 365 contains some of their most important business information. Protecting access to that environment should be treated accordingly.
Is Your Microsoft 365 Environment Properly Protected?
Simply enabling MFA does not necessarily mean your Microsoft 365 environment is configured to withstand today’s phishing techniques.
SwiftTech can help Australian businesses review and strengthen their IT and cybersecurity environment, including:
- Microsoft 365 and email security
- MFA and phishing-resistant authentication
- Microsoft Entra security configuration
- Essential Eight implementation
- Cybersecurity reviews
- Endpoint and device protection
- Backup and disaster recovery
- Network and Wi-Fi security
- Ongoing IT support and monitoring
Explore our business IT support and managed IT services, or speak with SwiftTech about reviewing your current Microsoft 365 and cybersecurity configuration.
Contact SwiftTech to discuss a cybersecurity or Microsoft 365 security review.
Frequently Asked Questions
Can hackers bypass Microsoft 365 MFA?
Some sophisticated phishing techniques can capture authenticated session tokens even after a user completes conventional MFA. These attacks do not mean MFA is ineffective. Businesses should continue using MFA while moving important accounts towards phishing-resistant authentication and additional access controls.
What is phishing-resistant MFA?
Phishing-resistant MFA uses authentication methods designed to prevent authentication information from being successfully reused through fraudulent login websites. Depending on the environment, examples can include FIDO2 security keys, passkeys, Windows Hello for Business and certificate-based authentication.
Should businesses stop using authenticator apps?
No. Conventional MFA remains considerably stronger than relying on passwords alone. Businesses should continue using MFA while assessing whether high-risk accounts, particularly administrator accounts, should move to phishing-resistant authentication methods.
What should I do if an employee enters Microsoft 365 details into a phishing website?
Treat the account as potentially compromised. Change appropriate credentials, revoke active sessions, review sign-in activity, authentication methods, mailbox rules and account permissions, and investigate whether the account has been used to contact customers or suppliers.
How can SwiftTech help protect Microsoft 365?
SwiftTech can assist businesses with cybersecurity assessments, Microsoft 365 security, MFA, Essential Eight implementation, data protection, backup and recovery, network security and ongoing IT support. Contact SwiftTech to discuss your current environment.
Authoritative Cybersecurity Resources
- Microsoft Threat Intelligence — AiTM token compromise research
- Microsoft — Phishing-resistant MFA for Microsoft Entra administrators
- Australian Cyber Security Centre — Small Business Cyber Security Guide
- Australian Cyber Security Centre — Passkeys
- Australian Cyber Security Centre — Preventing Business Email Compromise