Multi-factor authentication (MFA) remains one of the most important security controls organizations can deploy, but cybercriminals continue finding new ways to work around it. Rather than attacking passwords alone, today’s threat actors are increasingly exploiting the authentication process itself to gain access to Microsoft 365 environments.
Security researchers recently uncovered two sophisticated phishing toolkits designed to target Microsoft 365 users. These attacks demonstrate how quickly phishing campaigns are evolving, using legitimate authentication workflows and advanced social engineering techniques to bypass traditional defenses.
For managed service providers, this isn’t just another phishing story. It’s a reminder that protecting Microsoft 365 requires a comprehensive identity security strategy that goes well beyond simply enabling MFA.
Here are five insights MSPs should take away.
1. MFA Is Essential, But It Isn’t the Finish Line
For years, enabling MFA has been considered one of the biggest improvements organizations could make to their cybersecurity posture. While that remains true, attackers have shifted their focus toward manipulating authentication workflows instead of simply stealing passwords.
Modern phishing campaigns are becoming increasingly sophisticated by exploiting legitimate Microsoft authentication processes and convincing users to unknowingly grant attackers access.
MSPs should reinforce that MFA is still critical, but it should never be viewed as the only layer of protection.
MSP Action:
Review every client’s Microsoft Entra Conditional Access policies and recommend phishing-resistant authentication methods such as FIDO2 security keys or passkeys wherever practical.
2. Identity Has Become the New Security Perimeter
Traditional security focused heavily on protecting endpoints and networks. Today, attackers recognize that compromising a single Microsoft 365 identity can provide access to email, SharePoint, Teams, OneDrive, and countless business applications.
That makes identity one of the most valuable assets organizations possess.
As clients continue moving workloads into Microsoft 365, MSPs should place identity protection at the center of every security conversation.
MSP Action:
Offer recurring Microsoft 365 identity assessments that review authentication methods, Conditional Access policies, privileged accounts, and user permissions.
3. User Awareness Training Must Continue to Evolve
Many phishing awareness programs still focus primarily on spotting fake login pages or suspicious email links. Unfortunately, newer attacks often involve legitimate Microsoft pages or authentication requests that appear completely authentic.
Employees may unknowingly authorize attackers simply because they don’t understand how newer phishing techniques operate.
Security awareness training needs to evolve alongside today’s threats.
MSP Action:
Update client security awareness programs to include training on device-code phishing, unexpected authentication prompts, MFA fatigue attacks, and suspicious approval requests.
4. Faster Detection Can Limit Business Impact
One of the biggest challenges with identity-based attacks is how quickly they unfold. Once attackers gain access to a Microsoft 365 account, they often begin searching email, SharePoint libraries, Teams conversations, and cloud storage within minutes.
The faster suspicious activity is detected, the greater the opportunity to minimize damage.
Continuous monitoring has become just as important as preventative security controls.
MSP Action:
Deploy monitoring for impossible travel events, unusual sign-ins, excessive SharePoint downloads, new device registrations, privilege changes, and abnormal authentication activity.
5. MSPs Can Differentiate Through Identity Governance
Clients increasingly expect more than endpoint management and antivirus deployment. They want trusted advisors who can help them navigate an evolving cybersecurity landscape.
Identity governance—including authentication policies, least-privilege access, user lifecycle management, and ongoing security reviews—is becoming a valuable managed service that many organizations lack the internal resources to maintain.
MSPs that proactively strengthen Microsoft 365 identity security can create additional value while improving long-term client resilience.
MSP Action:
Develop a recurring identity governance service that includes Microsoft 365 security reviews, privilege audits, authentication assessments, security awareness training, and ongoing policy optimization.
What This Means for MSPs
The latest Microsoft 365 phishing kits demonstrate that cybercriminals continue adapting as security technologies improve. While MFA remains a foundational defense, attackers are increasingly targeting the authentication process rather than passwords themselves.
For MSPs, this reinforces the need to move beyond traditional security practices and adopt an identity-first approach. Combining strong authentication methods, Conditional Access, continuous monitoring, user education, and ongoing identity governance can significantly reduce client risk.
As Microsoft 365 adoption continues to grow, MSPs that proactively strengthen identity security will be better positioned to protect clients, differentiate their services, and reinforce their role as trusted cybersecurity advisors.




