MyElectricSparks MESMyElectricSparks MESMyElectricSparks MES
  • Home
  • Technology
    Technology
    Where technology meets innovation! Dive into our tech category, your one-stop destination for all things cutting-edge and digital. We’ve covered you, from the latest tech…
    Show More
    Top News
    Robot Company Will Pay $200,000 to Use Your Face and Voice on Its Robots ‘Forever
    July 17, 2024
    hair regrowth serum
    Taiwan Scientists Develop New Hair Regrowth Serum That Shows Results in Just 20 Days
    October 29, 2025
    Solar Tracking device project: A Step-by-Step Guide
    December 31, 2024
    Latest News
    China Unlikely to Overtake US in AI Race Within Five Years, Experts Say
    January 13, 2026
    China Develops Low-Cost Method to Extract Gold From Electronic Waste
    January 12, 2026
    China Reverse-Engineers the World’s Most Advanced Chip-Making Machine
    December 22, 2025
    Lung Cancer Was Treated With a Vaccine for The First Time In The UK
    December 21, 2025
  • Car News
    Car NewsShow More
    Škoda’s Superb diesel sedan
    Škoda Superb Diesel Sets Guinness World Record After Driving 2,831 KM on a Single Tank Across Europe
    3 Min Read
    Xiaomi SU7 electric car accident
    Xiaomi Car Catches Fire And Kills Man Trapped Inside Buring EV As Electric Door Handles Fail To Open
    5 Min Read
    Kubota hydrogen-powered-tractor-japan
    Japan Unveils First Hydrogen Tractor That Runs Without a Driver
    4 Min Read
    tesla accident Germany
    Father & Two Children Burn Alive In Tesla After Failed Rescue Attempt Due To Locked Doors
    5 Min Read
    Xiaomi SU7 Ultra prototype
    Xiaomi’s SU7 Ultra Sets Nürburgring Lap Record, Beats Porsche and Mercedes
    3 Min Read
  • AI News
    AI News
    This would cover news and updates about artificial intelligence and machine learning, including new developments and applications in the field.
    Show More
    Top News
    Grok Trump Elon Musk Death Penalty
    AI Chatbot Grok Says Trump And Elon Musk Deserve The Death Penalty
    February 25, 2025
    China light-speed chip
    Chinese Scientists Develop 100 GHz Chip Using Light Instead of Electricity
    March 9, 2025
    Animation with Artificial Intelligence
    The Emergence of Animation with Artificial Intelligence
    February 18, 2025
    Latest News
    China Unlikely to Overtake US in AI Race Within Five Years, Experts Say
    January 13, 2026
    Japan Says It Built The ‘World’s First AGI’ System That Can Learn New Tasks Without Any Human Guidance
    December 15, 2025
    Al Beats Doctors In An ‘Al Vs Doctors Battle’ Held In China, Takes 2 Seconds To Diagnose Health Problems
    December 10, 2025
    IBM Used AI to Fire Workers Then Realized It Needed to Hire More People
    October 25, 2025
  • Social News
    Social NewsShow More
    Six Flags Qiddiya City
    Saudi Arabia Completes Six Flags Qiddiya City, Opening Set for December 31
    5 Min Read
    Turkish husband liking other women photos on social media
    Turkey Court Rules That Liking Other Women’s Photos Can Harm Marriage
    6 Min Read
    Denmark ban social media children under 15
    Denmark Passes Law Banning Kids Aged 15 And Under From Using Social Media
    5 Min Read
    Chinese Airline Air Aunties
    Spring Airlines Faces Backlash in China for Hiring Married Women as “Air Aunties”
    6 Min Read
    NYC Restaurants Hire Filipino Cashiers via Zoom for $3.75 an Hour
    New York City Restaurants Are Now Hiring Cashiers From the Philippines Who Work From Zoom For $3.75 Per Hour
    5 Min Read
  • More
    • Apple
    • Bitcoin
    • Cybersecurity
    • Google
    • Graphic Cards
    • PlayStation
    • Games
    • Chrome
    • Robotics
    • Gadgets
    • Informational
    • Amazon
Search
  • Home
  • Technology
  • Car News
  • AI News
  • Social News
  • More
© 2025 MyElectricSparks by MES Media. All Rights Reserved.
Reading: Microsoft Issues Alert on the Rise of Multi-factor Authentication Security Threats: What You Need to Know
Share
Notification Show More
Font ResizerAa
MyElectricSparks MESMyElectricSparks MES
Font ResizerAa
Search
  • Home
  • Technology
  • Car News
  • AI News
  • Social News
  • More
    • Apple
    • Bitcoin
    • Cybersecurity
    • Google
    • Graphic Cards
    • PlayStation
    • Games
    • Chrome
    • Robotics
    • Gadgets
    • Informational
    • Amazon
Follow US
  • About
  • Editorial Guidelines
  • Privacy Policy
  • Cookies policy
© 2025 MyElectricSparks by THE MES TIMES LLC. All Rights Reserved.
Home » Microsoft Issues Alert on the Rise of Multi-factor Authentication Security Threats: What You Need to Know
Microsoft

Microsoft Issues Alert on the Rise of Multi-factor Authentication Security Threats: What You Need to Know

fatima khan
Last updated: December 29, 2024 3:16 pm
fatima khan
Share
Multi-factor Authentication Security
SHARE

Microsoft has provided several mitigations against multi-factor authentication attacks that could make it more difficult for remote workers.

Three years ago, multi-factor authentication attacks (MFA) were so rare that Microsoft needed decent statistics. This was mainly because only a few organizations had enabled MFA.

Microsoft has noticed an increase in token theft by attackers trying to bypass MFA as MFA usage rises, and attacks on passwords become more frequent.

These attacks involve the attacker compromising a token issued to someone who has already completed MFA and replaying that token to gain access to a new device. OAuth 2.0 identity platforms, such as Azure Active Directory (AD), are based on tickets. They aim to make authentication more straightforward and efficient for users while still resisting password attacks.

Microsoft also warns that token theft is dangerous as it doesn’t require technical skills, and detection is difficult. Additionally, the technique is relatively new, so few organizations have mitigations.

Microsoft states in a blog post, “Recently, Microsoft Detection and Response Team(DART) has witnessed an increase in attackers using token theft for this reason.”

“By replaying and compromising a token that was issued to an identity who has completed multi-factor authentication, a threat actor validates MFA. Access is then granted to the appropriate organizational resources.” This tactic concerns defenders as the token theft mitigations available to organizations must be more well-known and challenging to detect.

Accessing web applications protected by Azure AD requires that the user present a valid token. This token can be obtained after they sign into Azure AD with their credentials. For example, administrators can create a policy that requires MFA for users to log in to an account via a browser. The web application validates the token issued to the user and then opens access.

Microsoft explains that “when the user is phished the malicious infrastructure captures both his credentials and the token.”

The attacker could use the token and credentials to launch multiple attacks if they are stolen. In addition, Microsoft highlights cybercrime as the leading cause of financial loss due to email compromises in business.

Microsoft warns against “Pass-the cookie” attacks. This is where an attacker compromises a device to extract browser cookies created after authentication with Azure AD from a web browser. Then, to bypass security checks, the attacker transmits the cookie to another browser.

“Users who access corporate resources via personal devices are particularly at risk. Microsoft points out that personal devices are often less secure than corporate-managed ones and IT staff have limited visibility to identify a compromise. Remote workers who use personal devices are at greater risk.

Microsoft suggests that token theft attacks against MFA be prevented by reducing token lifetimes and session lengths. However, this comes at a cost to the user. These mitigations include:

  1. The session’s lifetime can be reduced, increasing the likelihood that a user will need to re-authenticate.
  2. Token theft is more common when threat actors reduce the token’s viable time.
  3. Microsoft recommends that users connecting to unmanaged devices use Conditional Access App Control in Microsoft Defender for Cloud Apps.

Microsoft recommends that users use certificate-based authentication for security keys such as Windows Hello for Business or FIDO2 security keys.

Users with high-level privileges, such as Global Domain admin, should have a separate cloud-only identity. If an attacker compromises systems on-premises, this will reduce the attack surface to the cloud. Microsoft stated that these identities should not be attached to a mailbox.

Microsoft acknowledges that it is only sometimes practical for organizations to enforce device compliance and location controls on all applications.

Microsoft Paint Gets a Boost: Say Hello to Layers and Transparency
Microsoft Introduces Innovative Button to PC Keyboards After Nearly 30 Years
Microsoft and OpenAI are collaborating to construct $100 Billion AI supercomputer called “Stargate”
The Future of Streaming: Is Netflix Abandoning Its Binge-Watching Model?
Microsoft’s AI, Copilot, Goes Rogue: Demands Worship from Users
Share This Article
Facebook Copy Link Print
Byfatima khan
Follow:
A brand new writer in the fields, Fatima has been taken under my electric spark's RGB- rich and ensures she doesn't engage in excessive snark on the website. It's unclear what command and Conquer are; however, she can talk for hours about the odd rhythm games, hardware, product reviews, and MMOs that were popular in the 2000s. Fatima has been creating various announcements, previews, and other content while here, but particularly enjoys writing regarding Products' latest news in the market she's currently addicted to. She is likely talking to an additional blogger with her current obsession right now.
Previous Article Qualcomm Snapdragon 782G Qualcomm Unveils the Latest Mid-Range Processor: Snapdragon 782G
Next Article Google Material You Toggle Design Google Unveils Revolutionary Material You Toggle Design in Docs, Sheets, and Slides
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

china-unlikely-to-beat-us-in-ai-next-five-years
China Unlikely to Overtake US in AI Race Within Five Years, Experts Say
AI and Machine Learning
China extract gold from electronic waste
China Develops Low-Cost Method to Extract Gold From Electronic Waste
Energy
Elon Musk Says Human Death Could Be a Solvable Scientific Problem
Elon Musk Says Human Death Could Be a Solvable Scientific Problem
Informational
Six Flags Qiddiya City
Saudi Arabia Completes Six Flags Qiddiya City, Opening Set for December 31
Social News

You Might also Like

Microsoft's Acquisition of Activision Blizzard
Microsoft

Microsoft’s Acquisition of Activision Blizzard: What It Means for Gamers and the Gaming Industry

fatima khan
fatima khan
4 Min Read
Microsoft

Microsoft Unveils GPT-4-Turbo in Copilot, Offering Enhanced AI Experience for Free

fatima khan
fatima khan
5 Min Read
Windows 11 400 million active devices
Microsoft

Windows 11 Hits 400 Million Active Devices, But Adoption Still Lags Behind Windows 10

fatima khan
fatima khan
6 Min Read
//

MyElectricSparks is a technology and innovation publication by MES Media with over 10 years of combined industry experience. Our panel of experts provides Latest News you can trust. We’re dedicated to providing you the coverage you need to make informed decisions in technology.

Popular Catogory

  • Tech
  • Gadgets
  • Cars
  • Social News
  • Mobile

Information

  • About
  • Editorial Guidelines
  • Privacy Policy
  • Cookies policy
MyElectricSparks MESMyElectricSparks MES
Follow US
© 2025 MyElectricSparks by THE MES TIMES LLC. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up