Once a password is valid, MFA is the next gate, and it falls in several ways: wear the user down with repeated push prompts, steal a token that already satisfied MFA, or register your own factor on an account that has none yet.
Register an attacker factor#
# when an account has no MFA method registered, enrol your own at first sign-in
# via https://aka.ms/mfasetup or the authentication-methods Graph endpoint
# (self-service registration with no existing factor is the classic takeover)
Manipulate methods with Graph#
# with the right role, add a phone/authenticator method to a victim and own their MFA
# POST /users/{id}/authentication/phoneMethods (Graph)
Exploitation notes#
- MFA fatigue: repeated push notifications until the user approves; works where number-matching is not enforced.
- A stolen PRT or refresh token already embodies MFA, so token replay sidesteps the prompt entirely (token theft).
- An account enrolled by the attacker (no prior factor) is a full takeover; sweep spray hits for MFA-not-registered state.
Tools#
- TeamFiltration / TokenTactics: capture tokens that carry the MFA claim.
- Graph / AADInternals: register or read authentication methods.