Your IT Consultant

Information Technology Blog
by John W. Simek, Vice President of Sensei Enterprises, Inc.

How to Mitigate 2FA Attack on Office 365

July 18, 2018

Users should enable and use two factor authentication (2FA) whenever it is available. Sure there are issues with using SMS as a second factor, but 2FA is by far better than just using a user ID and password. The attack vectors are constantly changing and the attacks on Office 365 are no exception. According to a TechRepublic report, multi-factor authentication may not be enough to protect Office 365 users. "Some Office 365 systems are vulnerable to a new cybersecurity attack vector, and multi-factor authentication may not be enough to stop it, according to research from Proofpoint."

To protect from this Exchange Web Services vulnerability, the suggestion for admins is to adhere to these three practices:

  1. Be fully migrated to O365
  2. Make sure to use Microsoft's own MFA
  3. Be in Modern Authentication mode

This Microsoft help article describes how to properly enable or disable modern authentication in Exchange Online.

E-mail: Phone: 703.359.0700
Digital Forensics/Information Security/Information Technology
https://www.linkedin.com/in/johnsimek
https://amazon.com/author/johnsimek
https://www.senseient.com