Automated Password Spraying Attack Office 365 Exchange Accounts

LM-5132 80 Reputation points
2024-08-27T18:17:15.08+00:00

We are currently experiencing a significant automated password-spraying attack on the Office 365 Exchange application targeting the accounts of two high-level employees.

The attack started at 1:36 am this morning and is still ongoing. There have been approximately 250 login attempts. The majority of the unauthorized attempts are from countries other than the US, but there are a few from within the US.

Our security protocols in place appear to be sufficient. This could go on throughout the night or even longer.

The attempted sign-ins are being blocked due to the following reasons:

  • Sign-in was blocked because it originated from an IP address associated with malicious activity
  • The account is locked due to multiple incorrect sign-in attempts

We have Multi-Factor Authentication (MFA) enabled for all users via SMS and the authenticator app.

In addition, I have created a conditional access policy that blocks sign-ins from countries outside of the US. This would be an extra measure to mitigate the risk. I can also apply it specifically to Office 365 Exchange.

I have not enabled this yet, and it is not yet tested.

  1. Do you think MFA and the default Microsoft security settings are enough to mitigate the attack?
  2. Are there any additional security measures we can implement that you recommend?

Thank you. User's image

User's image

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,493 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,449 questions
{count} votes

Accepted answer
  1. DURAI, JEYAKUMAR(Admin) 75 Reputation points
    2024-08-28T06:27:08.2766667+00:00

    Hi,

    1. Create Conditional access policies to block sign-ins from all the countries except where those two users are supposed to login from.
    2. Create "Named locations" in Entra ID and block access from the rest of the locations.

    Thanks!


1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 147.6K Reputation points MVP
    2024-09-02T19:11:58.27+00:00

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.