Real-world attacks, and the settings that stop them

Three patterns we see repeatedly — anonymized composites from real assessments

1. Business email compromise: the CEO's "urgent invoice"

A finance officer receives an email from the CEO's real mailbox: pay this supplier today, new bank details attached. The money leaves. Nobody hacked anything in the movie sense — weeks earlier the CEO's password was phished, the account had no MFA enforcement, and the attacker sat quietly reading email, learning the company's invoice rhythm, before striking with perfect timing.

What stops it: MFA enforced for all users (not just enabled — enforced), sign-in risk policies flagging the login from an unfamiliar country, and mailbox auditing that would have surfaced the attacker's inbox rules. All three appear in a Secure Score assessment; in ours, unenforced MFA is almost always gap #1.

2. Ransomware through the side door: legacy authentication

An organization proudly rolls out MFA. Six months later, ransomware. How? An old protocol — IMAP, SMTP AUTH, or an ancient ActiveSync client — doesn't support MFA at all, and it was still enabled. The attacker password-sprayed weak passwords against that legacy endpoint, walked in without ever seeing an MFA prompt, and escalated from there.

What stops it: blocking legacy authentication via conditional access — typically a one-afternoon change. "We have MFA" and "MFA protects every path in" are different claims; the assessment tests the second one.

3. The login page that wasn't

An employee clicks a link in a convincing "document shared with you" email and lands on a pixel-perfect copy of the Microsoft 365 sign-in page. Password entered, harvested, replayed by the attacker within minutes — sometimes together with a stolen session token that sidesteps basic MFA.

What stops it: phishing-resistant MFA methods, conditional access requiring compliant devices for sensitive apps, and short session lifetimes so stolen tokens expire fast. Each maps to specific Secure Score controls with step-by-step remediation.

The pattern behind the patterns

None of these attacks exploited a zero-day. Every one walked through a configuration gap that Microsoft's own tooling had already flagged — in a score nobody was reading. That is the entire case for assessing before an incident does it for you.

How exposed is your tenant? Find out in two minutes with the free, read-only Microsoft 365 security assessment.

Run the free assessment