The cloud has no or — but it has attacks on the identity itself. Almost all of them start the same way: a weak password, a tired user or a clicked link.
Four common attacks
- Password spray — one common password (like Summer2026!) tried against many users, slowly, to avoid lockouts.
- MFA fatigue — the attacker already knows the password and sends dozens of approval prompts until the user taps “Approve”.
- Token theft (AiTM) — a phishing page sits between the user and Microsoft and steals the session cookie after MFA.
- Consent phishing — a malicious app asks the user to “allow access” to their mailbox, no password needed.
Where to look
- Sign-in logs — many failures (error 50126) from a few IP addresses = password spray.
- Risky sign-ins in Identity Protection — Impossible travel, Anomalous token.
- Audit logs — “Consent to application” for an unfamiliar app.
Defenses
- Number matching in Authenticator — stops MFA fatigue.
- FIDO2 / passkeys — resistant to phishing and AiTM.
- Block legacy authentication and use risk-based Conditional Access rules.
- Do not let users approve apps themselves — only an admin approves.