Azure CLI: 81 million login attempts and 78 compromised accounts

Colleagues, I’d like to draw attention to a cybersecurity attack targeting Azure CLI.
I came across a campaign in which threat actors carried out more than 81 million login attempts and gained access to at least 78 Microsoft accounts across 64 organizations.
The key issue was the legacy OAuth ROPC flow. It helped bypass part of the Conditional Access policies and worked even where MFA was not enforced across all scenarios.
My takeaway is simple: MFA must be enabled for all users, all cloud apps, and all client application types. Azure CLI should also be restricted for non-admin users, and access policies should be reviewed.
Why this matters: MFA does not protect if it is implemented incompletely.
How is legacy-flow control configured in your environment?
#cybersecurity #Azure #MFA #Microsoft

