M365 Social Engineering Attacks: Why Your Microsoft 365 Security Fails Against Pretexting in Teams

M365 Social Engineering Attacks: Why Your Microsoft 365 Security Fails Against Pretexting in Teams

(00:00:00) Microsoft 365 Security Alert
(00:00:06) The Weakness in MFA
(00:00:52) Case File 1: Teams Phishing Inside the Perimeter
(00:02:02) Corrective Doctrine for Teams Security
(00:06:53) Case File 2: Device Code Flow MFA Evasion
(00:08:26) Strengthening Device Code Security
(00:13:37) Case File 3: App Consent Abuse
(00:15:27) Governance of App Permissions
(00:21:03) Case File 4: SharePoint Link Abuse
(00:28:06) Token Theft and Session Replay

In this episode of M365.fm, Mirko Peters dissects how modern social engineering walks straight through your “secure” Microsoft 365 setup — using Teams, device codes, and OAuth consent — and shows how to redesign policies, detections, and user protocol so pretexting fails on impact.

WHAT YOU WILL LEARN
  • How attackers weaponize Teams external federation to impersonate IT and harvest MFA approvals
  • Why device code flows and “helpful” verification messages bypass everything your users think they know about phishing
  • How consent phishing and ungoverned app registrations quietly turn “Sign in with Microsoft” into data exfiltration
  • Why your current Conditional Access, Safe Links, and risk policies don’t see the full pretext chain
  • How to redesign external access, MFA, and Teams policies so chat cannot be used as an elevation vector
  • How to build concrete KQL detections that correlate external DMs, MFA spikes, device code usage, and mailbox/file activity
  • How to teach users verification rituals that work under stress instead of vague “be careful” advice
THE CORE INSIGHT

Most Microsoft 365 security programs still think in malware, bad URLs, and brute force. Today’s attackers don’t argue with your controls — they use your own channels, branding, and MFA prompts against you.
Teams, device code, and consent flows are all legitimate; the difference between normal and hostile is ceremony: who can contact whom, which flows are allowed, how risk and identity policies respond, and what users are trained to do in the moment.
This episode argues that social engineering defense in M365 is not a “user awareness” problem but a systems design problem — and that you can design friction that kills pretext attacks before users have to be perfect.

WHY YOUR M365 SECURITY FAILS AGAINST SOCIAL ENGINEERING
  • Teams external access is “on by habit,” so any tenant can DM any user with an “IT Support” avatar
  • MFA fatigue is possible because there is no hard rule that “support never asks you to approve a prompt”
  • Device code flows are allowed everywhere, with no dedicated policies, detections, or user guidance
  • OAuth consent is under‑governed: users and even admins can grant high‑risk permissions to unverified apps
  • Identity risk, collaboration channels, and data activity are monitored separately, so the attack chain never appears as one incident
WHAT YOU’LL TAKE AWAY IN PRACTICE
  • Concrete Teams external federation and Safe Links settings that cut off unsolicited pretext DMs
  • Conditional Access designs that treat Teams and device code flows as elevation vectors, not “just apps”
  • Detection patterns that correlate chat, MFA bursts, deviceAuth endpoints, and mailbox/SharePoint changes
  • A verification ritual (phrases, call‑back channels, “never read codes in chat”) that users can actually follow under pressure
  • Governance patterns for verified publishers, app consent, and named locations that shrink the social engineering surface
WHO THIS EPISODE IS FOR

This episode is essential for Microsoft 365 security engineers, identity architects, SOC analysts, and IT leaders responsible for user protection in cloud collaboration.
If you’ve already rolled out MFA, Conditional Access, and Defender, but still worry that one good pretext in Teams or one device code prompt could undo it all, this conversation will give you an end‑to‑end blueprint to fix that.A

BOUT THE HOST

Mirko Peters is a Microsoft 365 consultant and digital workplace architect focused on building social‑engineering‑resistant security architectures on the Microsoft cloud.
Through M365.fm, Mirko shares real incident patterns, governance models, and detection strategies that help organizations close the gap between “Zero Trust on slides” and how attacks actually unfold in Microsoft 365.
























Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(857)

Microsoft Purview Insider Risk Management - Simply Explained

Microsoft Purview Insider Risk Management - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Insider Risk Management, Microsoft's intelligent solution for identifying risky user behavior...

24 Heinä 0s

Microsoft Purview Information Protection - Simply Explained

Microsoft Purview Information Protection - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Information Protection, the foundation of Microsoft's data classification and protection stra...

24 Heinä 0s

Microsoft Purview Data Loss Prevention (DLP) - Simply Explained

Microsoft Purview Data Loss Prevention (DLP) - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Data Loss Prevention (DLP), one of the most important security capabilities in Microsoft 365 ...

24 Heinä 0s

Microsoft Entra Private Access - Simply Explained

Microsoft Entra Private Access - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Entra Internet Access, Microsoft's modern cloud-native approach to secure internet connectivity that ...

24 Heinä 0s

Microsoft Graph Delta Queries - Simply Explained

Microsoft Graph Delta Queries - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Graph Delta Queries, one of the most powerful features for building efficient synchronization solutio...

24 Heinä 0s

Responsible AI Is Good Business — Featuring Wiebke Apitzsch

Responsible AI Is Good Business — Featuring Wiebke Apitzsch

Artificial intelligence is transforming every industry, but successful AI adoption requires far more than deploying the latest models or building autonomous agents. In this episode of M365.fm, Mirko P...

24 Heinä 0s

Microsoft Graph Webhooks - Simply Explained

Microsoft Graph Webhooks - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Graph Webhooks, one of the core building blocks for creating modern, event-driven Microsoft 365 appli...

24 Heinä 0s

Microsoft Graph Change Notifications - Simply Explained

Microsoft Graph Change Notifications - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Graph Change Notifications, one of the most important capabilities for building modern, event-driven ...

24 Heinä 0s

Suosittua kategoriassa Politiikka ja uutiset

aikalisa
uutiscast
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
rss-podme-livebox
rss-seksicast
rss-vaalirankkurit-podcast
otetaan-yhdet
politiikan-puskaradio
aihe
rikosmyytit
rss-kovin-paikka
rss-kaikki-uusiksi
tervo-halme
rss-asiastudio
rss-girls-finish-f1rst
rss-varsinaista-puhetta