MFA and Password Reset Become the Attack Path

Microsoft Entra ID recovery is no longer a safety rail when attackers can turn it into account takeover. In this campaign, Storm-2949 uses self-service password reset and MFA approval prompts to seize privileged Microsoft 365 and Azure accounts, then move into high-value data and cloud infrastructure. Microsoft says the actor targets IT staff and senior leaders, obtains Entra ID access through social engineering, then resets passwords, strips MFA, and enrolls its own Authenticator. After takeover, the group used Microsoft Graph, OneDrive, SharePoint, and Azure resources to enumerate identities and pull large volumes of sensitive files. The practical shift is that recovery workflows now sit on the attack path. If an attacker can persuade a user to approve reset prompts, the usual trust placed in MFA does not hold, and the compromise can extend from one privileged identity into broader Microsoft 365 and Azure exposure.

Part of the PlainSec briefing for 2026-05-19

Sources