MFA is not the finish line
Turning on multi-factor authentication is the single best security decision most businesses make. It is also routinely bypassed, and the reasons are worth understanding before you call identity done.
If a business has done one thing, it is usually multi-factor authentication. Rightly so. Nothing else available at that price removes as much risk, and it stops the overwhelming majority of credential attacks dead.
The problem is what happens next, which is that identity gets ticked off. MFA is on, so accounts are safe. Then an account gets taken over anyway, and nobody can work out how.
The three ways it goes around you
Fatigue. An attacker with a valid password pushes approval requests until someone taps accept, usually at 7am while getting dressed. Number matching helps. Not sending approvals for logins from unexpected places helps more.
Session theft. MFA authenticates the login. It does not protect the token issued afterwards. Steal that cookie, replay it, and no second factor is requested because from the platform’s point of view the login already happened. This is what most modern phishing kits actually do.
The accounts nobody enrolled. The service account that runs the backup job. The shared mailbox. The old admin account kept “just in case”. The contractor whose access was set up in a hurry. MFA coverage is a percentage, and the gap is where the attention goes.
None of these mean MFA failed. They mean MFA answered one question and the others were left open.
What actually closes it
Conditional access, not just a second factor. Decide what a normal login looks like for your business and treat the rest as suspect. A sign-in from a managed device, in the country you operate in, during hours you operate, is low-risk. The same account from an unmanaged device on the other side of the world is not, and it should be blocked or challenged harder rather than allowed through on a tap.
Phishing-resistant factors where it counts. App approvals and codes are vulnerable to a convincing proxy. Passkeys and hardware keys are not, because the credential is bound to the site it was created for. You do not need them everywhere. You do need them on the accounts that could ruin your week: finance approvers, IT administrators, the director.
A real inventory of privileged accounts. Most environments have more administrators than the business would guess, several of them people who needed it once for a specific job in 2022. Standing admin rights are the thing an attacker is looking for.
Coverage as a number you check. Not “we have MFA” but “97% of accounts, and here are the four exceptions and why”. The exceptions are the risk, so they should be a list somebody owns rather than an unknown.
The awkward one: your own helpdesk
Every control above can be defeated by a phone call to whoever resets passwords, if that person can be talked into it. Someone claiming to be a staff member, locked out, on the road, and under pressure, is a very effective attack and it requires no technical skill at all.
If your reset process relies on recognising a voice, it is not a process. Verify through a channel the caller did not choose, and write down what “verified” means so the person on the phone at 4:45pm on a Friday is not making the call alone.
Where to stop
None of this is an argument for buying more security products. It is an argument that identity is a configuration exercise you finish rather than a switch you flip, and most of the remaining work is in tenancy settings you already pay for.
MFA on is the right first move. It is just not the last one.