Real-Time Active Directory (AD) Authentication attack

Manish Kumar 1 Reputation point
2020-09-13T04:05:23.72+00:00
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,664 questions
{count} votes

1 answer

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,236 Reputation points Microsoft Employee
    2020-09-14T07:28:54.913+00:00

    @Manish Kumar Thanks for reaching out. The attack mentioned in the article has been targeted to users to look legitimate and use the benefit of less secured Authentication methods (Like No MFA or other security keys Like FIDO).

    Any Advance protection tools look for suspicious flag like blocked flagged domains, spoof intelligence and lots of other things. While we do have many services at place to prevent phishing and other known attacks, like
    Anti-Fishing protection in Microsoft 365
    Spoof Intelligence in EOP and Configure anti-phishing policies in EOP

    but despite all these things a hacker would find something to attack unless we build the core strong with something they cannot have.

    If you look at this image you would know the importance of password less authentication

    24442-image1.png

    So if we are really to prevent these kind of things, you must consider :
    https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-passwordless

    The organization should also educate their high risk user about this kind of attempts and use this attack simulator to spread awareness :
    https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulator?view=o365-worldwide

    -----------------------------------------------------------------------------------------------------------------

    If the suggested response helped you resolve your issue, please do not forget to accept the response as Answer and "Up-Vote" for the answer that helped you for benefit of the community.

    2 people found this answer helpful.