>> All posts

Microsoft 365 password spraying against exposed logins

The short version: When your applications sign in through Microsoft (login.microsoftonline.com), they share the most-sprayed identity surface on the internet — and weak or reused passwords without MFA let attackers quietly guess their way into cloud accounts.

What you need to know

There's no CVE here — this is about identity and the credentials behind it. Microsoft 365 / Entra ID authentication is everywhere, and that ubiquity makes it a constant target: attackers spray common and breached passwords against Microsoft logins at massive scale, using employee email addresses that are easy to guess or harvest.

  • How they find it — a redirect to the Microsoft login portal reveals that an application authenticates through Microsoft 365.
  • How they use it — automated, low-and-slow spraying with common and previously-breached passwords across many known or guessed employee accounts, staying under lockout thresholds.
  • What it leads to — one valid credential can reach email, files, and other cloud resources, and provide a foothold to expand across the tenant.

How serious we see it

Moderate — by default, with real upside risk. Microsoft accounts protected by enforced MFA and strong, unique passwords are well-defended, which is why we don't rate every Microsoft login "Critical." But spraying against Microsoft 365 is relentless and well-documented, so any account with a weak or reused password and no second factor is a live path into the cloud tenant. The reassuring part: MFA and conditional-access policy are entirely in your hands.

What to do

  • Enforce MFA on every account — the single highest-value control; it defeats spraying even when a password is known.
  • Use conditional access and smart lockout — block legacy authentication and throttle suspicious sign-ins.
  • Kill weak and reused passwords — enforce strong, unique credentials and check them against known-breached lists.
  • Monitor sign-in logs — alert on spray patterns (many accounts, few passwords, from unusual locations).
  • Confirm your exposure first — identify which applications authenticate through Microsoft and whether MFA is enforced everywhere.

How BreachRisk sees it

BreachRisk discovers applications that authenticate through Microsoft the way an attacker would — by crawling your external footprint and following the redirect to the Microsoft login — and then, where authorized, goes a step further than a scanner: it safely attempts a bounded, rate-limited authentication check using employee emails with exposed (breach-corpus) and common credentials, within strict non-disruptive limits rather than a brute-force flood. That's the honest difference between detecting Microsoft authentication and demonstrating whether an account actually holds.

References

See your cyber risk, proven.