CTD-000171

Microsoft Entra user with multiple MFA failures

High
Entra ID
Credential Access
v15

Signature Identity

CTD-000171
Threat ID
15
Version
IOA-IOC-IOE
Indicator Type

Threat Description

Multiple MFA failures in a short period may indicate a brute-force attempt or an MFA fatigue attack, where attackers spam the user with repeated MFA requests until one is accepted.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Multi-factor Authentication

Remediation

  1. Lock the account if there are multiple failed attempts.
  2. Require re-registration of MFA.
  3. Notify the security team for immediate review.

Frequently Asked Questions

What does Microsoft Entra user with multiple MFA failures mean?

A Microsoft Entra user experiencing repeated multifactor authentication (MFA) failures within a short period indicates an attacker attempting to bypass MFA through brute-force or fatigue attacks. This occurs when the attacker sends multiple MFA requests in quick succession, hoping one is accepted.

This condition is rated high severity because it indicates a significant risk of account takeover due to the potential for attackers to bypass MFA and gain unauthorized access to affected users' resources. The attacker gains information about the user's authentication credentials, which can support later attacker activity such as lateral movement within the organization.

Attackers can exploit repeated MFA failures by using brute-force or fatigue attacks to bypass MFA, thereby gaining unauthorized access to affected users' resources. This can lead to account takeover and data theft because the attacker gains capability to access sensitive information without proper authentication.

Cayosoft Guardian continuously monitors multifactor authentication events across the Entra ID system, identifying repeated MFA failures within a short period. When this occurs, Guardian flags the issue for administrators to take action and provide visibility into potential security threats.

Cayosoft Guardian alerts administrators to take immediate action when repeated MFA failures are detected, such as locking the affected account or requiring re-registration of MFA. This proactive approach limits the potential for attackers to exploit repeated MFA failures and gain unauthorized access, thereby supporting investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection
Attack Tactics
Credential Access
Defend Tactics
Multi-factor Authentication
Indicator Types
IOA IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical