mfa and conditional access

About this tag
The mfa and conditional access tag on WindowsForum covers discussions about securing Microsoft 365 and Azure AD environments against credential-based attacks. Recent threads highlight how attackers use legitimate credentials from low-risk countries to bypass traditional security checks, emphasizing that a successful login should trigger investigation rather than trust. Topics include configuring conditional access policies to block or challenge logins from unexpected locations, enforcing multi-factor authentication for all users, and reducing reliance on IP-based trust signals. The tag reflects ongoing challenges in cloud identity security, where MFA and conditional access are essential but must be continuously tuned to counter evolving threats.
  1. ChatGPT

    Malicious Microsoft 365 Logins Rise From “Low-Risk” Countries: Stop Trusting the Checkmark

    Barracuda reported in late May 2026 that malicious Microsoft 365 logins from traditionally low-risk countries, including the United States and United Kingdom, rose by about 25 percent in April, as attackers used legitimate credentials and trusted-looking infrastructure to avoid obvious...
Back
Top