MFA Fails on the Legacy OAuth Path

MFA and Conditional Access do not help if a tenant still lets an app trade a password directly for a token. In this campaign, attackers used the legacy OAuth ROPC flow to skip the normal interactive sign-in step, so the MFA prompt never had a chance to stop them. Huntress says the activity ran from June 12 to June 26 and produced more than 81 million login attempts, with at least 78 Microsoft accounts taken over across 64 organizations. The campaign targeted Azure CLI sign-ins, and the compromised tenants included cases where MFA was present but not applied to the flow being abused, or was only enforced for some users, some apps, or some locations. The risk is the tenant authentication path itself, not one weak account or one bad app. If password-based OAuth or other legacy flows are still allowed, a clean patch or a working MFA policy does not close the gap that lets stolen credentials become valid Microsoft 365 access.

Part of the PlainSec briefing for 2026-07-02

Sources