⚙ Build in progress — some links may break, some copy may shift. We'd appreciate the heads-up: [email protected]
version 26.5.1 · Western Australia · Est. 2011·Microsoft Partner & Reseller · HP, Yealink, Ubiquiti, Kyocera
— Security · Identity & access

MFA & identity

Identity is your perimeter.

Multi-factor authentication is now the bare minimum, not the answer. Adversary-in-the-middle toolkits like EvilProxy and Tycoon sit between the user and Microsoft's sign-in page, capturing both credentials and the resulting session token after MFA completes. The attacker replays the token to impersonate the user, MFA notwithstanding. The defence has to be deeper: Conditional Access policies bound to device compliance, Continuous Access Evaluation revoking sessions on risk events, and phishing-resistant authentication for the accounts that matter. Done well, the user experience improves: fewer prompts, more security, no theatre.

<30s
AiTM kit token-replay window
100%
Admin accounts on FIDO2 / Hello
0
Standing privileged-access accounts
// THE THREAT

What is actually going wrong.

Adversary-in-the-middle phishing kits steal session tokens after MFA. VPN authentication is now a consistent entry vector — full domain compromise often follows within hours of one successful login. SMS MFA can be SIM-swapped. Push-notification fatigue attacks rely on the user eventually approving by mistake.

// HOW WE SOLVE

The whedo.it approach.

Entra ID with Conditional Access policies that bind sessions to compliant devices. Continuous Access Evaluation (CAE) so that a risky sign-in immediately revokes the session, not at the next 60-minute token refresh. Phishing-resistant auth (FIDO2, Windows Hello, passkeys) enforced for all admin accounts and high-risk roles. Number-matching MFA replaces simple push-approve. SMS auth retired.

// HOW WE PROTECT

Ongoing protection.

Identity Protection risk scoring runs continuously, flagging unusual sign-in patterns and impossible travel. Privileged Identity Management (PIM) means standing admin rights are eliminated — admin access becomes just-in-time, time-bound, and audited. Sign-in audit logs are reviewed monthly; suspicious activity escalates to whedo.it within minutes.

Explore the other security topics, or zoom back out.

Each of the six topics covers a layer of the security stack. They work together — phishing defence assumes good identity, identity assumes endpoint compliance, endpoint compliance assumes the tenant is locked down properly.

Get a posture review for this layer.

30 minutes, your environment, no deck. Warren walks the mfa & identity surface with you and tells you what it would take to lock it down properly. No follow-up unless you ask.

5.0
★★★★★ on Google · loading…
Read all on Google →