Wealth management

Over 99% of password spray attacks use legacy authentication

Microsoft's own data says more than 99% of password spray attacks arrive through legacy authentication.

1 min readOriginally posted on LinkedIn

Microsoft's own data says more than 99% of password spray attacks arrive through legacy authentication. Not clever zero-days. Old protocols most firms forgot were still switched on.

Here's the part that catches people off guard: legacy authentication can't do MFA. Those older mail protocols — POP, IMAP, SMTP — were built to accept a username and password and nothing else. So when an attacker finally guesses a password, nobody's phone buzzes. The door just opens.

I see this most often at firms that did everything right. MFA rolled out, strong passwords, the works. Then there's the scanner that emails statements, the CRM plugin someone configured in 2019, an old phone still syncing a departed advisor's mail. Every one of those is a side door MFA never reaches.

What happens next is rarely dramatic. No ransom note. They add a quiet forwarding rule and read client correspondence for weeks. You find out when a client calls about wire instructions you never sent.

Two things worth doing. Pull your Entra sign-in logs and filter for legacy protocols — the list of accounts still using them is usually shorter than you'd fear. Then turn on the block policy Microsoft now ships for exactly this.

It's an afternoon of work. Worth doing before your next cyber renewal.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions