During their keynote at the RSA Security Conferencelast week, Microsoft engineers said that 99.9% of the compromised accounts they detect each month are not using Microsoft multi-factor authentication (MFA). has repeatedly emphasized that this method of protection can prevent most (mostly automated) attacks on accounts .
The company said that about 0.5% of accounts are compromised each month. In January 2020, that figure amounted to about 1.2 million accounts.
A breach of an account can cause a lot of problems, especially when that account is a corporate. Of these highly sensitive accounts, only 11% had MFA enabled.
In most cases, account breaches occur after other, usually simple attacks . Most Microsoft account breaches started with password spraying, a technique in which an attacker chooses a common and easy password and combines it with various usernames until they get the right combination and gain access to an account.

A second breach method, according to Microsoft, is password replays, a technique in which an attacker takes credentials that have been leaked by other hackers or companies and tries them to see if they can gain access to Microsoft accounts. After all, using the same passwords on different accounts is a common occurrence, and hackers know this.
"We know that 60% of users reuse passwords. It's very common," said Lee Walker, a Microsoft executive.
Walker said that the vast majority of password spraying and password replay attacks targeting Microsoft accounts target older authentication protocols, such as SMTP, IMAP, POP and others.
More specifically, 99% of all password spraying attacks and 97% of password replay attacks are performed via legacy protocols.
Microsoft says that these protocols do not support multi-factor authentication (MFA), so they are ideal for hackers, since they can compromise accounts much more easily.
Companies need to disable these protocols if they want to stay secure.
According to Microsoft, disabling these protocols resulted in a 67% reduction in compromised accounts.
However, according to the company, this is not enough. All companies should enable and require authentication (MFA) on user accounts.
Microsoft has said since last year that both companies and ordinary users should use MFA, because this solution can block 99.9% of breaches.

