Password spraying to a cloud mailbox
A low-and-slow password spray against a cloud identity provider lands a valid login, defeats weak MFA, and reaches email and cloud roles — an identity-first attack path.
Scenario
An authorized assessment of a cloud tenant's identity exposure. You may test the published authentication portals against an agreed user list. The objective is to show whether credential-guessing plus MFA weaknesses lead to mailbox and cloud access.
- 1
Reconnaissance
Build the user list and naming scheme
Determine the email/username format and assemble an in-scope list of valid accounts to target, keeping strictly to the approved users.
DetectionAccount-enumeration probing against the login/autodiscover endpoints is visible in sign-in telemetry.
MitigationReduce username-enumeration signals, and monitor authentication endpoints for enumeration patterns.
- 2
Credential Access
Spray a small number of likely passwords
Try one or two common/seasonal passwords across the whole user list with long delays, staying under lockout thresholds — the essence of spraying versus brute force.
DetectionMany accounts each seeing a single failed login from one source in a short window is the classic spray signature.
MitigationBan common passwords, enforce smart lockout, require phishing-resistant MFA, and alert on spray patterns.
- 3
Credential Access / Defense Evasion
Get past weak MFA
T1621 Multi-Factor Authentication Request GenerationT1556.006 Modify Authentication Process: Multi-Factor AuthenticationWhere a sprayed credential is valid but MFA is enabled, assess whether push-notification fatigue or a weak second factor allows access — reporting MFA strength as a finding rather than coercing a real user.
DetectionBursts of MFA push requests to one user, and approvals at odd hours, are detectable; number-matching MFA defeats fatigue.
MitigationUse phishing-resistant MFA (FIDO2), enable number matching, and alert on repeated push prompts.
- 4
Collection
Access the mailbox
With a valid session, demonstrate read access to the compromised user's cloud mailbox, documenting the exposure (sensitive mail, delegation, rules) rather than harvesting content.
DetectionMailbox sign-ins from new locations/clients and new inbox rules are visible in audit logs.
MitigationConditional-access by device/location, disable legacy auth, and alert on new mail-forwarding rules.
References azure-ad-security - 5
Privilege Escalation / Persistence
Expand access across the tenant
T1098.002 Account Manipulation: Additional Email Delegate PermissionsT1098.003 Account Manipulation: Additional Cloud RolesAssess whether the foothold identity can grant itself additional mailbox delegation or cloud roles, demonstrating how one mailbox becomes broader tenant access.
DetectionNew delegate permissions and role assignments are high-value audit events.
MitigationLeast-privilege roles, approval workflows for role changes, and monitoring of delegation grants.
Key takeaways
- Identity is the new perimeter: a weak password plus weak MFA beats the firewall entirely.
- Spraying stays under lockout thresholds — detect it by the fan-out across many accounts, not failures per account.
- Phishing-resistant MFA and conditional access break this path at the MFA and mailbox stages.