Automated Password Spraying Attack Office 365 Exchange Accounts

LM-5132 290 Reputation points
2024-08-27T18:17:15.08+00:00

We are currently experiencing a significant automated password-spraying attack on the Office 365 Exchange application targeting the accounts of two high-level employees.

The attack started at 1:36 am this morning and is still ongoing. There have been approximately 250 login attempts. The majority of the unauthorized attempts are from countries other than the US, but there are a few from within the US.

Our security protocols in place appear to be sufficient. This could go on throughout the night or even longer.

The attempted sign-ins are being blocked due to the following reasons:

  • Sign-in was blocked because it originated from an IP address associated with malicious activity
  • The account is locked due to multiple incorrect sign-in attempts

We have Multi-Factor Authentication (MFA) enabled for all users via SMS and the authenticator app.

In addition, I have created a conditional access policy that blocks sign-ins from countries outside of the US. This would be an extra measure to mitigate the risk. I can also apply it specifically to Office 365 Exchange.

I have not enabled this yet, and it is not yet tested.

  1. Do you think MFA and the default Microsoft security settings are enough to mitigate the attack?
  2. Are there any additional security measures we can implement that you recommend?

Thank you. User's image

User's image

Exchange Online
Exchange Online
A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Answer accepted by question author
  1. DURAI, JEYAKUMAR(Admin) 85 Reputation points
    2024-08-28T06:27:08.2766667+00:00

    Hi,

    1. Create Conditional access policies to block sign-ins from all the countries except where those two users are supposed to login from.
    2. Create "Named locations" in Entra ID and block access from the rest of the locations.

    Thanks!

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 159.7K Reputation points MVP Volunteer Moderator
    2024-09-02T19:11:58.27+00:00

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.