Don’t worry this was just a test, but it could have been worse, I could have been a malicious hacker who now has complete access to your Microsoft 365 account. The worse thing you would be totally unaware that this has happened.
But I have 2FA!
That used to be good enough, in fact a password used to be enough to secure your account. But times have changed and now basic 2FA just isn’t enough.
You’ve followed all the necessary security steps:
You’ve setup a complex password
You don’t use the same password on any other site/service
You use 2FA
All of that is great, but it is no longer enough to prevent malicious hackers getting your login details and using it to access your account.
Phishing Resistant 2FA
Phishing-resistant Multi-Factor Authentication (MFA) is a highly secure authentication method designed to fortify user accounts against phishing attacks.
Unlike traditional MFA, which can still be vulnerable to phishing attempts, this approach incorporates multiple layers of protection to ensure enhanced security.
It employs advanced techniques making it significantly more challenging for attackers to impersonate users.
Phishing resistant technologies include:
Biometric authentication
Hardware tokens
Push notifications to trusted devices
Passkeys
Adam Tachauer-Yates
Founder of WP Agency Support and really concerned with security.