Contact Us
Next webinarQuickBooks on AutopilotThursday October 15, 3:00 PM CDTRegister Now
Oct 6, 2026

MFA Was On. They Got In Anyway: How Attackers Bypass MFA in Microsoft 365

A business owner turns on multi-factor authentication (MFA), checks the box on the cyber insurance form, and moves on. A few months later, someone in accounting gets an email from a vendor's real address asking to update banking details. The vendor's mailbox was taken over. So was one of yours.

"But we have MFA" is the most common thing we hear after a breach. MFA was on. The attacker got in anyway.

MFA is still one of the best things you can do for your business. It stops the large majority of password attacks cold. But attackers have adapted, and the ones targeting small and mid-sized businesses now go around MFA instead of through it. Here's how they do it, and what closes each gap.

The myth: MFA means nobody can get in without my phone

MFA protects the moment you sign in. It checks that the person typing your password also has your phone. Once that check passes, Microsoft 365 hands your browser a session token, a digital pass that says "this person already proved who they are." That pass is what keeps you signed in for days without prompting you again.

Attackers figured out that they don't need your password or your phone. They need that pass.

Across the businesses we support, identity alerts (suspicious sign-ins, stolen sessions, unexpected changes to how someone signs in) nearly tripled from August to September of this year. Almost every one involved an account that had MFA turned on.

Four ways attackers bypass MFA

1. They steal the session after you sign in

This is the most common MFA bypass today. It's called an adversary-in-the-middle attack. You click a link in a convincing email and land on what looks exactly like the Microsoft sign-in page. It's a relay. You type your password, approve the MFA prompt on your phone, and the real Microsoft signs you in. The fake page sits in the middle and copies your session token on the way through.

Now the attacker has a valid pass. They don't need your password again and they never see an MFA prompt. We've seen stolen sessions used from the other side of the world within hours of the real user signing in from their desk.

Diagram of how a stolen session lets an attacker bypass MFA in Microsoft 365

2. They add their own phone to your account

Once inside, a smart attacker makes sure they can come back. They open your security settings, remove your MFA methods, and register their own authenticator app. From then on, your account's "second factor" is a phone in someone else's pocket. Changing your password won't lock them out, because they can approve the reset.

3. They hide in your inbox with rules

Inbox rules are the quietest part of these attacks, and the part that costs money. We regularly find rules like these on compromised accounts:

  • A rule with a blank or nonsense name that moves incoming messages to a folder nobody opens.
  • A rule that moves any email mentioning payments or wire transfers to an obscure folder.
  • A rule that deletes replies from a coworker, so nobody sees "did you really change your bank account?"

The attacker reads your conversations for a few weeks, learns how your invoices work, and then sends one well-timed message from your real address.

4. MFA was never enforced

This one surprises owners the most. In assessments of new clients, we often find MFA that's set up but not switched on: users enrolled but the policy disabled, or a Conditional Access policy left in "report-only" mode that watches sign-ins and blocks nothing. Sometimes it covers one person. Everyone believes they're protected because they remember setting it up once.

What closes the gaps

None of these fixes are exotic. They're settings and habits that most small business tenants have never had someone turn on.

Table of four MFA bypass methods and the settings that close each one

Confirm MFA is enforced for everyone. Not enrolled, enforced. Every user, every admin account, every shared login that can sign in. If you don't know how to check this, that's a sign it hasn't been checked.

Use phishing-resistant sign-in where you can. Passkeys, Windows Hello for Business and hardware security keys don't work on a fake sign-in page, because they're tied to the real Microsoft address. Start with owners, finance staff and anyone who can approve payments.

Bind sessions to known devices. Microsoft 365 can require that sign-ins come from company-managed devices, and its token protection feature ties a session to the computer that created it. A stolen session then won't work from someone else's laptop. These are Conditional Access settings, and they need to be planned and tested before they're enforced.

Watch for changes to sign-in methods. A new authenticator added to an account, especially right after a sign-in from an unfamiliar location, should raise an alert someone looks at the same day.

Review inbox rules. Rules that forward mail outside the company, move financial keywords, or have blank or nonsense names are red flags. Someone should be checking for them automatically, not once a year.

Verify payment changes by phone. Any request to change bank details gets a call to a number you already have on file. Never the number in the email.

Why "we have MFA" isn't the end of the conversation

Cyber insurance applications now ask detailed questions about MFA, and carriers check the answers after a claim. If your application says MFA is enforced on email and remote access, and the claims investigator finds a policy in report-only mode, that's a problem nobody wants to discover after a wire goes out.

The attacks above also don't trip your antivirus. Nothing malicious ever runs on a computer. Everything happens in Microsoft 365 with valid credentials, which is why so many of these go unnoticed for weeks.

Using Google Workspace instead?

None of this is unique to Microsoft. A fake sign-in page can relay a Google login and copy the session just as easily, and attackers hide in Gmail with filters and forwarding addresses the same way they use Outlook inbox rules. The fixes carry over:

  • Enforce 2-Step Verification for every user in the Google Admin console, and move owners and finance staff to passkeys or security keys.
  • Limit access to company devices with Google's Context-Aware Access.
  • Keep Chrome up to date on Windows. Since May 2026, Google ties Workspace sessions to the computer they started on, which makes a stolen session much harder to reuse. It needs a recent version of Chrome and the security chip that's standard on most Windows 11 computers.
  • Review Gmail filters and forwarding addresses for anything nobody on your team set up.

Where SafePoint IT comes in

This is what identity threat detection and response (ITDR) is for. On our managed clients, we monitor Microsoft 365 for the signs above: stolen sessions being replayed, new authenticators added, suspicious inbox rules, and sign-ins from places your team has never been. When something fires, an engineer isolates the account, kills the session and cleans up the rules, usually before the attacker has finished reading the inbox.

We also check that MFA is enforced, not just enrolled, as part of every new client's onboarding. More on the basics in our guides to what MFA is and how it works and why MFA matters for business security.

Not sure your MFA is doing its job?

If you'd like a straight answer on whether MFA is enforced across your company and whether anyone would notice a stolen session, book a 15-minute call with our team. No pitch, just a look at where you stand.

Book a free 15-minute call

Frequently Asked Questions

Can MFA be bypassed?
Yes. MFA protects the sign-in itself, but attackers can steal the session token issued after you sign in, trick users into approving prompts, or take advantage of MFA that was set up but never enforced. MFA still blocks most password attacks, so keep it on, but pair it with monitoring and phishing-resistant sign-in methods.
Can attackers bypass MFA in Google Workspace too?
Yes. The same stolen-session and hidden-filter techniques work against Google accounts. Google now binds Workspace sessions to the device in Chrome on Windows, which makes stolen sessions harder to reuse, but you still need 2-Step Verification enforced for every user, access limited to company devices, and regular reviews of Gmail filters and forwarding.
What is an adversary-in-the-middle attack?
It's a phishing attack where a fake sign-in page relays your login to the real Microsoft site in real time. You complete MFA normally, and the fake page copies the session token that Microsoft issues. The attacker then uses that token to open your mailbox without needing your password or phone.
What is token theft in Microsoft 365?
Token theft is when an attacker steals the session token your browser receives after a successful sign-in. That token proves you already passed MFA, so whoever holds it can access your account until the session expires or is revoked. Revoking sessions and binding tokens to company devices are the main defenses.
How do I know if someone added their own authenticator to my account?
Check your security info at the Microsoft My Sign-Ins page for any phone or app you don't recognize. Your administrator can also review audit logs for recent changes to authentication methods. If you find one you didn't add, report it immediately, because changing your password alone won't remove it.
Does changing my password stop an attacker who stole my session?
Not always. A stolen session can keep working until it's revoked, and an attacker who added their own authenticator can approve a password reset. After a compromise, an administrator should revoke all sessions, remove unknown sign-in methods, check inbox rules and then reset the password.

Technology Insights

SafePoint IT team standing together in a modern Chicago office

SafePoint IT Named to the 2026 Inc. 5000 List

SafePoint IT has been named to the 2026 Inc. 5000 list, the annual ranking of...
Read More
Business owner reviewing rising AI costs on a laptop dashboard

Why Your Team's AI Bills Are Higher Than They Should Be (And the Habits That Actually Fix It)

If your business runs on Claude, ChatGPT, or any other AI assistant at scale, you've...
Read More
Office manager looking at her phone after an unexpected sign-in alert

MFA Was On. They Got In Anyway: How Attackers Bypass MFA in Microsoft 365

A business owner turns on multi-factor authentication (MFA), checks the box on the cyber insurance...
Read More
chevron-down linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram