Your organization has MFA. Your users have strong passwords. Conditional access is enabled. So how is an attacker still getting into the account?
This is one of the uncomfortable questions security teams are facing in 2026.
The problem is that attackers don't always need to defeat MFA.
Sometimes, they simply go around it.
Recent attacks against Microsoft 365 environments have included device-code phishing, session-token theft, password spraying and other techniques designed to obtain authenticated access even when MFA is enabled.
And that changes the identity security conversation.
The question is no longer:
"Do we have MFA?"
It is:
"What happens after authentication succeeds?"
MFA Protects the Login. What Protects the Session?
Think about what happens when you sign into a SaaS application.
You enter your credentials.
You complete MFA.
The application verifies you.
Then it gives your browser a session token.
From that point forward, the application often uses that session to recognize you.
That's convenient.
But it also creates another security problem.
If an attacker obtains that authenticated session, they may not need your password or another MFA challenge to continue operating as you.
The attacker isn't necessarily breaking MFA.
They're stealing the proof that MFA already happened.
This is why session-token theft and session hijacking have become important identity-security concerns.
The Attack Doesn't Always Look Like a Login Attack
Imagine this.
An employee signs into Microsoft 365 normally.
MFA succeeds.
Nothing looks suspicious.
A few minutes later, an attacker starts using a stolen session.
Now the security team sees:
An authenticated user accessing a SaaS application.
A new device or unusual location.
Unusual mailbox activity.
A privileged resource being accessed.
Large amounts of data being downloaded.
Suspicious communication from an endpoint associated with the account.
Individually, some of these events may not trigger a high-confidence incident.
Together, they tell a very different story.
That's where identity security becomes a security operations problem.
The Real Problem Is the Context Around the Identity
Identity systems can tell you that authentication happened.
Endpoint security can tell you what happened on the device.
Network security can tell you where the traffic went.
Cloud security can tell you what resources were accessed.
But an account takeover rarely stays inside one of those categories.
The attacker may move through all of them.
That's why modern detection needs to connect:
Identity + Endpoint + Network + Cloud + SaaS + User Behavior
Instead of asking:
"Was this login legitimate?"
Security teams increasingly need to ask:
"Does everything this identity is doing after the login make sense?"
This Is Where UEBA Becomes Important
User and Entity Behavior Analytics, or UEBA, isn't simply about detecting a suspicious login.
It's about understanding behavior.
For example:
A finance employee normally accesses a small group of applications during business hours.
Suddenly, the same identity accesses several unfamiliar resources, downloads large amounts of data, and starts interacting with systems it has never used before.
The login itself might have been valid.
The behavior isn't.
That's the kind of distinction behavioral analytics can help security teams identify.
And this is where identity signals become much more useful when correlated with the rest of the security environment.
Why SIEM Alone Isn't the Whole Answer
SIEM remains critical because security teams need centralized visibility and historical security data.
But collecting identity logs isn't the same as understanding an identity attack.
Consider this chain:
MFA authentication
↓
New device
↓
Unusual user behavior
↓
Suspicious endpoint activity
↓
Abnormal network connection
↓
Sensitive data access
↓
Potential account takeover
If every signal lives in a different security product, the analyst has to manually connect the dots.
That costs time.
And during an active attack, time matters.
Where Seceon OTM Fits
This is one of the areas where Seceon's Open Threat Management (OTM) Platform can be relevant.
OTM brings together capabilities including:
SIEM + XDR + UEBA + SOAR + Threat Intelligence + Threat Hunting
within a unified security operations platform.
That matters because an identity anomaly shouldn't necessarily be investigated as an isolated identity event.
It can be correlated with endpoint activity.
Network behavior.
Cloud activity.
Threat intelligence.
And other security signals.
For example:
An unusual login occurs.
UEBA identifies behavior outside the normal baseline.
XDR connects the identity activity with an endpoint anomaly.
Threat intelligence adds context around suspicious infrastructure.
SIEM provides the broader event history.
SOAR can help automate appropriate response actions.
Now the analyst isn't looking at six unrelated alerts.
They're looking at a potential attack chain.
The identity is the starting point. The surrounding behavior tells the story.
The Biggest Identity Security Mistake
One of the biggest mistakes organizations can make is treating authentication as the finish line.
Authentication should be the beginning of continuous trust evaluation.
A user successfully passing MFA doesn't automatically mean:
- Every subsequent action is legitimate
- Every device associated with the session is trustworthy
- Every resource request is normal
- Every application interaction is expected
- Every session should remain valid
Security needs to continue after authentication.
That's especially important as organizations rely more heavily on cloud applications, SaaS platforms, APIs and remote access.
What Should Security Teams Monitor After MFA?
If you're reviewing your identity-security strategy in 2026, don't stop at MFA deployment.
Look at what happens after the user authenticates.
Session Activity
Monitor unusual sessions, devices, locations and access patterns.
User Behavior
Look for activity that significantly differs from the user's normal behavior.
Privilege Changes
Watch for unexpected privilege escalation or access to sensitive resources.
Application Activity
Monitor unusual SaaS and cloud application usage.
Endpoint Signals
Correlate identity activity with what is happening on the user's device.
Network Behavior
Look for unusual destinations, connections or traffic patterns associated with the identity.
Data Access
Watch for abnormal downloads, transfers or access to sensitive information.
The important word here is:
Correlation.
One event rarely tells the whole story.
What About Phishing-Resistant MFA?
This doesn't mean MFA is no longer useful.
Quite the opposite.
Strong authentication remains an important security control, and phishing-resistant methods can significantly improve resistance to credential-based attacks.
But identity security shouldn't depend on a single control.
Even with stronger authentication, organizations still need visibility into:
What happened after access was granted?
Because attackers don't always need to compromise the authentication mechanism itself.
They may compromise the endpoint.
Steal an active session.
Abuse an authorized identity.
Exploit excessive permissions.
Or operate through a trusted application.
Why This Matters for MSSPs
For an MSSP, identity monitoring becomes even more complicated.
Imagine managing security for 50 customers.
Each customer has:
Different identity providers.
Different SaaS applications.
Different users.
Different access policies.
Different normal behavior.
Different risk profiles.
An MSSP can't realistically investigate every identity event manually.
The platform needs to help separate:
Normal behavior → Suspicious behavior → Potential attack
and provide enough context for analysts to act.
This is where a unified security operations approach can become valuable.
With Seceon OTM, MSSPs can bring SIEM, XDR, UEBA, SOAR and threat intelligence into a centralized security operations workflow rather than treating identity activity as a completely separate security problem.
The Identity Perimeter Is Changing
The old security model was largely:
Protect the network perimeter.
Then it became:
Protect the endpoint.
Then:
Protect the identity.
But today, none of these exist in isolation.
An identity can be compromised through an endpoint.
An endpoint can be controlled through a malicious application.
A compromised identity can access cloud resources.
Cloud activity can lead to data exposure.
And network activity can reveal the attack.
The modern security perimeter is increasingly a connected ecosystem.
That's why security teams need visibility across the entire attack chain.
The Question Security Teams Should Be Asking
Don't ask only:
"Is MFA enabled?"
Ask:
"If an attacker gets past the login, how quickly would we know?"
That's a much harder question.
And it's the one that matters.
Because authentication tells you who successfully entered.
Security operations need to determine whether that person is actually behaving like themselves.
That's where identity analytics, UEBA, XDR, SIEM, threat intelligence and automated response start working together.
And that's the direction Seceon is taking with OTM.
Not just detecting the login.
Understanding what happens next.
FAQ: MFA Bypass and Identity Security
Can attackers bypass MFA?
Yes. Attackers can use techniques such as adversary-in-the-middle phishing, device-code phishing, MFA fatigue, credential theft and session-token theft to obtain or abuse authenticated access.
Does MFA prevent account takeover?
MFA significantly reduces the risk of many credential-based attacks, but it isn't a complete account-takeover defense. Attackers can target sessions, tokens, endpoints, applications and users after authentication.
What is session-token theft?
Session-token theft occurs when an attacker obtains a token representing an already authenticated session and uses it to impersonate the legitimate user.
What is UEBA?
UEBA stands for User and Entity Behavior Analytics. It analyzes behavioral patterns to identify activity that deviates from what is considered normal for a user or entity.
How can SIEM help detect identity attacks?
SIEM can centralize identity, endpoint, network, cloud and application events, making it easier to investigate activity across different security domains and build a timeline of an incident.
How does Seceon OTM help with identity-related threats?
Seceon OTM combines SIEM, XDR, UEBA, SOAR, threat intelligence and threat hunting to correlate security signals across different environments. This can help security teams connect unusual identity behavior with endpoint, network and other security events.
Is Seceon OTM useful for MSSPs?
Yes. OTM is designed to support centralized and multi-tenant security operations, helping MSSPs monitor and investigate security activity across multiple customer environments.
MFA Was Never Supposed to Be the Whole Security Strategy
MFA is important.
Strong authentication is important.
Identity controls are important.
But none of them answer the most important question by themselves:
What is this identity doing right now?
That's the question modern security operations need to answer continuously.
Because the attacker doesn't care whether your dashboard says:
"MFA: Enabled."
They care whether they can operate as a trusted identity after authentication.
And that's why identity security is no longer just an IAM problem.
It's a SOC problem.
Top comments (0)