> The hack involves the NTIA’s office software, Microsoft’s Office 365. Staff emails at the agency were monitored by the hackers for months, sources said. > The hackers are “highly sophisticated” and have been able to trick the Microsoft platform’s authentication controls, according to a person familiar with the incident, who spoke on condition of anonymity because they were not allowed to speak to the press. > “This…
>"able to trick the Microsoft platform’s authentication" So they social engineered the password, and if MFA was on it was push based MFA and the user just clicked OK to all popups on their phone?
Encryption: Yes.
Multi-factor authentication: Yes.
Do they care if the MFA is simply the user pecking at buttons like a bird trained with seeds: No.
There is a real problem with Azure AD MFA. Unlike the consumer MFA, it shows you exactly zero information about the source of the information. None. You get a choice of "approve" or "do not approve". You don't get any input information for making this decision.
Hacking this is trivial. If you know someone's password, you just have to occasionally try logging in. Eventually the user will accidentally click approve even though they didn't trigger the authentication.
You'd assume that nobody would ever fall for something like this, because surely nobody would be so stupid as to approve an MFA prompt they didn't trigger.
Meanwhile, my Microsoft Authenticator app triggers randomly about 5-10 times per day because every single MS app insists on "reauthenticating" me every 24 hours. So I'll be sitting at my desk and my phone will pop it up randomly. I'll look up, and sure enough, Teams wants me to re-MFA for some stupid reason.
I'm paranoid enough that I'll always reject these MFA prompts and then start the login cycle manually, but most people would just peck the button like a trained bird.
Similarly, I've run scripts before that needed 6 MFA prompts to complete (don't ask). I ran the script once and it asked 7 times... uh-oh. Is this an Azure bug, or a hacker from China? How could I possibly know?! The information is not provided to me!
This is Microsoft's fault, 110%, and I dare anyone here to argue otherwise.
So instead of reaching for the downvote button, make your case on how "yes, yes, yes, yes" is not a security disaster below in the comments please.