Skip to main content
AD Academy
Microsoft Entra ID (Azure AD)
Intermediate12 minLast updated: Topic 6 of 6

Attacks on Entra ID: what attackers do in the cloud

Password spray, MFA fatigue, token theft and malicious app consent — and how to spot them.

Not read

What you will learn here

  • Four common attacks on cloud identities
  • Where they show up in the logs
  • Which defense closes each one

Worth reading first:Conditional Access in practice: your first four rules

The cloud has no or — but it has attacks on the identity itself. Almost all of them start the same way: a weak password, a tired user or a clicked link.

Four common attacks

  • Password spray — one common password (like Summer2026!) tried against many users, slowly, to avoid lockouts.
  • MFA fatigue — the attacker already knows the password and sends dozens of approval prompts until the user taps “Approve”.
  • Token theft (AiTM) — a phishing page sits between the user and Microsoft and steals the session cookie after MFA.
  • Consent phishing — a malicious app asks the user to “allow access” to their mailbox, no password needed.

Where to look

  • Sign-in logs — many failures (error 50126) from a few IP addresses = password spray.
  • Risky sign-ins in Identity Protection — Impossible travel, Anomalous token.
  • Audit logs — “Consent to application” for an unfamiliar app.

Defenses

  • Number matching in Authenticator — stops MFA fatigue.
  • FIDO2 / passkeys — resistant to phishing and AiTM.
  • Block legacy authentication and use risk-based Conditional Access rules.
  • Do not let users approve apps themselves — only an admin approves.

Check yourself

Which defense stops MFA fatigue?

Was this page helpful?