← All posts post

MFA Is a Data Point, Not a Verdict

IdentityOctober 2026 · 1 min read

Microsoft's 2025 Digital Defense Report: more than 97% of identity attacks are password spray or brute force, and identity-based attacks rose 32% in the first half of 2025.

Same report: MFA still blocks more than 99% of unauthorized access attempts.

So why do accounts still get taken over?

  • MFA isn't on everything. Legacy protocols, service accounts, the exception someone approved two years ago.
  • Session theft. Adversary-in-the-middle phishing kits steal the session after the user passes MFA. The password was never the prize.
  • Consent grants. The user authorizes a malicious app, and the app doesn't need their password at all.

So when a sign-in log says "MFA satisfied," my investigation doesn't end there. It's one data point. The next questions are where the session went, what it touched, and what changed in the mailbox afterward.

Sources

  1. Microsoft Digital Defense Report 2025 (PDF)
  2. The Record coverage