Microsoft 365How-To & HardeningRetrospectives

How to Defeat AiTM Phishing With Compliant-Device and Phishing-Resistant MFA Policies

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2022, written in 2026 with the benefit of hindsight.

Adversary-in-the-middle phishing steals session cookies after users complete MFA. Two controls stop it: phishing-resistant authentication and compliant-device requirements. Here is how to deploy both in Entra ID.

Control 1: Phishing-resistant MFA

Passkeys, FIDO2 security keys, Windows Hello for Business and certificate-based authentication are bound to the legitimate site's origin. A proxy can't relay them.

  1. Enable passkeys (FIDO2) and Windows Hello for Business in the authentication methods policy.
  2. Create a Conditional Access policy using authentication strength: Phishing-resistant MFA.
  3. Apply it first to administrators, then executives, finance and other high-risk users.
  4. Expand to all users as registration grows.

Control 2: Require compliant or hybrid-joined devices

If access requires a device that's managed and compliant, a stolen cookie replayed from the attacker's machine fails.

  1. Enroll devices in Intune with compliance policies.
  2. Create a Conditional Access policy requiring Require device to be marked as compliant (or Microsoft Entra hybrid joined) for Office 365 and other sensitive apps.
  3. For personal devices, use app protection policies and limit to web access with session controls.

Supporting controls

  • Token protection (where supported) binds sessions to devices.
  • Defender for Office 365 Safe Links and anti-phishing policies reduce delivery of phishing emails.
  • Identity Protection risk policies respond to "attacker in the middle" and anomalous token detections.
  • Continuous Access Evaluation speeds up revocation.

Rollout tips

  • Start in report-only mode and review sign-in logs.
  • Give users a clear registration path and help desk support.

Verify

Test with a controlled phishing simulation using an AiTM-capable framework in a lab, confirming sign-in fails from unmanaged devices.

prevent aitm phishingAiTM phishing campaign2022

More on this story