
You're on the right track, you'll want to set a Conditional Access policy that forces MFA for All users. Also, you should not only pull the MFA sessions but also require a re-register.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi All
One of our Microsoft 365 user email has been compromised. Someone is able to send emails that appear to be from the user from that account to many recipient via his address book (Blue/Red cube) as follows.
But stranger problem occurred, perpetrator had injected users into "Active user" @ Microsoft 365 admin center from addresses book of our compromised user as follows
User type=Guest @ Microsoft Entra admin center
After the problem found
I checked user authentication methods, MFA ready, looking good as follows.
Login log after user modified password, red cube=perpetrator, green cube=Our user.
Question & leakage fix
Could all please help me with this?
Thanks a lot
You're on the right track, you'll want to set a Conditional Access policy that forces MFA for All users. Also, you should not only pull the MFA sessions but also require a re-register.