Deloitte's Email Breach (Sept 2017): An Admin Account Without MFA
Retrospective: this article looks back at events from September 2017, written in 2026 with the benefit of hindsight.
In September 2017, The Guardian reported that Deloitte, one of the world's largest accounting and consulting firms, had suffered a breach of its global email system. Attackers had accessed confidential emails and some client information.
How it happened
According to reports at the time, attackers gained access through an administrator account for Deloitte's email environment, hosted in Microsoft's Azure cloud. The account required only a password — it did not have two-step verification. With administrator access, the attackers could reach mailboxes and other data across the system. Deloitte said only a small number of clients were affected.
Why it mattered
The breach was a stark example of the most important rule in cloud identity: administrative accounts must have strong authentication. Cloud administration is reachable from anywhere on the internet. A single password protecting global admin rights is a single point of failure.
It also showed that sophisticated professional services firms — the same firms advising clients on cybersecurity — could miss basic controls.
Lessons for Microsoft 365 and Entra ID
- MFA on every privileged account, no exceptions. Today, phishing-resistant methods (passkeys, FIDO2 keys) are the standard for admins.
- Minimize standing admin rights. Privileged Identity Management grants admin roles just in time.
- Separate admin accounts from daily-use accounts.
- Monitor admin activity with alerts for new admin role assignments and unusual admin sign-ins.
In hindsight
Microsoft now requires MFA for admin portals such as the Azure portal and Entra admin center. The rule that would have prevented this breach has become a platform default — but only for some entry points, and only for the type of MFA it enforces.
- How to Protect Global Admin Accounts in Microsoft 365 and Entra ID How-To & Hardening
- Detecting Compromised Admin Account: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: Privileged Accounts Are the Keys to the Kingdom CIO Briefings