Privileged Microsoft 365 access can be compromised with a password alone
Evidence
Two Global Administrator accounts and one billing administrator account were observed without enforced MFA. Conditional Access does not currently protect privileged roles.
Business impact
Compromise of one privileged credential could give an attacker control of email, identity, billing, and security configuration, creating a credible path to business-email compromise and broader tenant takeover.
Required action
Enforce phishing-resistant MFA for all privileged roles, remove standing administrator access where it is not required, and establish two emergency access accounts with monitored use.
Owner · Technology Lead