---
title: Identity Security Beyond MFA | NSP
description: Token theft, MFA fatigue, and helpdesk impersonation target what comes after. Here's what NZ businesses should understand about modern identity attacks.
image: https://blog.nsp.co.nz/hubfs/NZ%20business%20leader%20reviewing%20Microsoft%20Entra%20ID%20identity%20security%20dashboard%20on%20laptop%2c%20representing%20identity%20security%20monitoring%20beyond%20MFA%20for%20New%20Zealand%20organisations.png
---

[![NSP\_Logo](https://blog.nsp.co.nz/hs-fs/hubfs/NSP_Logo.webp?width=118&height=76&name=NSP_Logo.webp)](https://nsp.co.nz/)

- [Home](https://nsp.co.nz/)
- Solution
  
  ##### [Cybersecurity](https://nsp.co.nz/cybersecurity/)

    - [Incident Response](https://nsp.co.nz/cybersecurity/incident-response/)
    - [Penetration testing (pen tests)](https://nsp.co.nz/cybersecurity/penetration-testing/)
    - [Security Assessments](https://nsp.co.nz/cybersecurity/cyber-security-assessments/)
    - [Secure Email](https://nsp.co.nz/cybersecurity/secure-email-services/)
    - [Security Awareness](https://nsp.co.nz/cybersecurity/cyber-security-awareness-training/)
    - [Security Operations Centre](https://nsp.co.nz/cybersecurity/security-operations-centre/)
    - [VCISO Strategy Services](https://nsp.co.nz/cybersecurity/vciso-strategy-services/)
    - [Cyber Insurance Assessments](https://nsp.co.nz/cybersecurity/cyber-insurance-assessments/)
    - [Vulnerability Management](https://nsp.co.nz/cybersecurity/vulnerability-management/)
    - [Ransomware Protection & Recovery](https://nsp.co.nz/cybersecurity/ransomware-protection-and-recovery/)
    - [Tabletop Exercise](https://nsp.co.nz/tabletop-exercise/)

  ##### [Modern Workplace](https://nsp.co.nz/modern-workplace/)

    - [AI Governance & Compliance](https://nsp.co.nz/modern-workplace/ai-governance-compliance/)
    - [Remote Workforce](https://nsp.co.nz/modern-workplace/remote-workforce/)
    - [Microsoft Co-Pilot](https://nsp.co.nz/modern-workplace/microsoft-365-co-pilot/)
    - [Consultation](https://nsp.co.nz/modern-workplace/consultation/)
    - [Productivity & Innovation](https://nsp.co.nz/modern-workplace/productivity-and-innovation/)
    - [Business Intelligence](https://nsp.co.nz/modern-workplace/business-intelligence/)
    - [Security](https://nsp.co.nz/modern-workplace/security/)

  ##### [Cloud](https://nsp.co.nz/cloud/)

    - [Managed Services](https://nsp.co.nz/cloud/managed-services/)
    - [Migration](https://nsp.co.nz/cloud/migration/)
    - [Storage](https://nsp.co.nz/cloud/storage/)
    - [PBX/Voice](https://nsp.co.nz/cloud/pbx-voice/)
    - [Security](https://nsp.co.nz/cloud/security/)

  ##### [Managed Services](https://nsp.co.nz/managed-services/)

    - [Managed IT](https://nsp.co.nz/cloud/managed-it/)
    - [Helpdesk](https://nsp.co.nz/managed-services/helpdesk/)
    - [Business Intelligence](https://nsp.co.nz/managed-services/business-intelligence/)
    - [Business Innovation](https://nsp.co.nz/managed-services/business-innovation/)
    - [Managed Network](https://nsp.co.nz/managed-services/managed-network/)

  ##### [Network Performance](https://nsp.co.nz/network-performance/)

    - [Firewall as a Service](https://nsp.co.nz/network-performance/firewall-as-a-service/)
    - [Network Intelligence](https://nsp.co.nz/network-performance/network-intelligence/)
    - [Network Roadmaps](https://nsp.co.nz/network-performance/network-roadmaps/)

  ##### [Backup](https://nsp.co.nz/backup/)

    - [Data Backup](https://nsp.co.nz/backup/data-backup/)
    - [Data Consultancy](https://nsp.co.nz/backup/data-consultancy/)
    - [Data Retention Solutions](https://nsp.co.nz/backup/data-retention-solutions/)
    - [Cloud Storage](https://nsp.co.nz/backup/cloud-storage/)
    - [Ransomware Protection & Recovery](https://nsp.co.nz/backup/ransomware-protection-and-recovery/)

  ##### [Professional Services](https://nsp.co.nz/professional-services/)

    - [Services](https://nsp.co.nz/professional-services/services/)
    - [Consultancy](https://nsp.co.nz/professional-services/consultancy/)
    - [Project Delivery](https://nsp.co.nz/professional-services/project-delivery/)

  ##### [Cybersecurity](https://nsp.co.nz/cybersecurity/)

    - [Incident Response](https://nsp.co.nz/cybersecurity/incident-response/)
    - [Penetration testing (pen tests)](https://nsp.co.nz/cybersecurity/penetration-testing/)
    - [Security Assessments](https://nsp.co.nz/cybersecurity/cyber-security-assessments/)
    - [Secure Email](https://nsp.co.nz/cybersecurity/secure-email-services/)
    - [Security Awareness](https://nsp.co.nz/cybersecurity/cyber-security-awareness-training/)
    - [Security Operations Centre](https://nsp.co.nz/cybersecurity/security-operations-centre/)
    - [VCISO Strategy Services](https://nsp.co.nz/cybersecurity/vciso-strategy-services/)
    - [Cyber Insurance Assessments](https://nsp.co.nz/cybersecurity/cyber-insurance-assessments/)
    - [Vulnerability Management](https://nsp.co.nz/cybersecurity/vulnerability-management/)
    - [Ransomware Protection & Recovery](https://nsp.co.nz/cybersecurity/ransomware-protection-and-recovery/)
    - [Tabletop Exercise](https://nsp.co.nz/tabletop-exercise/)

  ##### [Modern Workplace](https://nsp.co.nz/modern-workplace/)

    - [AI Governance & Compliance](https://nsp.co.nz/modern-workplace/ai-governance-compliance/)
    - [Remote Workforce](https://nsp.co.nz/modern-workplace/remote-workforce/)
    - [Microsoft Co-Pilot](https://nsp.co.nz/modern-workplace/microsoft-365-co-pilot/)
    - [Consultation](https://nsp.co.nz/modern-workplace/consultation/)
    - [Productivity & Innovation](https://nsp.co.nz/modern-workplace/productivity-and-innovation/)
    - [Business Intelligence](https://nsp.co.nz/modern-workplace/business-intelligence/)
    - [Security](https://nsp.co.nz/modern-workplace/security/)

  ##### [Cloud](https://nsp.co.nz/cloud/)

    - [Managed Services](https://nsp.co.nz/cloud/managed-services/)
    - [Migration](https://nsp.co.nz/cloud/migration/)
    - [Storage](https://nsp.co.nz/cloud/storage/)
    - [PBX/Voice](https://nsp.co.nz/cloud/pbx-voice/)
    - [Security](https://nsp.co.nz/cloud/security/)

  ##### [Managed Services](https://nsp.co.nz/managed-services/)

    - [Managed IT](https://nsp.co.nz/cloud/managed-it/)
    - [Helpdesk](https://nsp.co.nz/managed-services/helpdesk/)
    - [Business Intelligence](https://nsp.co.nz/managed-services/business-intelligence/)
    - [Business Innovation](https://nsp.co.nz/managed-services/business-innovation/)
    - [Managed Network](https://nsp.co.nz/managed-services/managed-network/)

  ##### [Network Performance](https://nsp.co.nz/network-performance/)

    - [Firewall as a Service](https://nsp.co.nz/network-performance/firewall-as-a-service/)
    - [Network Intelligence](https://nsp.co.nz/network-performance/network-intelligence/)
    - [Network Roadmaps](https://nsp.co.nz/network-performance/network-roadmaps/)

  ##### [Backup](https://nsp.co.nz/backup/)

    - [Data Backup](https://nsp.co.nz/backup/data-backup/)
    - [Data Consultancy](https://nsp.co.nz/backup/data-consultancy/)
    - [Data Retention Solutions](https://nsp.co.nz/backup/data-retention-solutions/)
    - [Cloud Storage](https://nsp.co.nz/backup/cloud-storage/)
    - [Ransomware Protection & Recovery](https://nsp.co.nz/backup/ransomware-protection-and-recovery/)

  ##### [Professional Services](https://nsp.co.nz/professional-services/)

    - [Services](https://nsp.co.nz/professional-services/services/)
    - [Consultancy](https://nsp.co.nz/professional-services/consultancy/)
    - [Project Delivery](https://nsp.co.nz/professional-services/project-delivery/)
- [About us](https://nsp.co.nz/about-us/)
- Resources
  
    - [Blog](https://blog.nsp.co.nz/)
    - [Webinar](https://nsp.co.nz/webinar/)

    - [Blog](https://blog.nsp.co.nz/)
    - [Webinar](https://nsp.co.nz/webinar/)
- [Contact us](https://nsp.co.nz/contact-us/)

[0508 010 101](tel:0508%20010%20101)[hello@nsp.co.nz](mailto:hello@nsp.co.nz)

- Home
- Blogs
- Identity Security Beyond MFA | NSP

### Identity Security Beyond MFA | NSP

![](https://blog.nsp.co.nz/hubfs/NSP_Logo_Primary%20logo_CMYK_1-2.png)

 NSP Marketing

 27 September 2026

 15 min 

Read

# MFA Protects Your Login. What Protects Everything Around It?

 

Layer3 NZ's 2026 threat landscape analysis made an observation that's worth sitting with: "For many businesses, the breach no longer starts with a dramatic 'hack.' It starts with a password reset, an MFA change, a convincing phone call, or a stolen token."

None of those entry points involve breaking MFA. None of them require stealing a password. All of them are active in New Zealand right now, documented by the NCSC, and targeting organisations that believe their identity security is largely sorted.

The question worth asking isn't whether your MFA is configured. It's what happens to an employee identity once the login screen is behind them - and whether your business has visibility into any of it.

 

## You Secured the Password. What About Everything Around It?

The traditional model of identity attack had a straightforward logic: steal the password, log in, access whatever the account can reach. This model shaped how most businesses thought about identity security - create strong passwords, add MFA, and the account is protected.

That model still exists. Phishing and credential harvesting were the most common incident type reported to the NCSC in Q1 2026, with 437 incidents in a single quarter. Basic credential theft remains common precisely because it works when MFA isn't consistently deployed.

But alongside it, a different model has developed - one that doesn't depend on stealing credentials at all.

Attackers have recognised that MFA protects the login. After the login, the authentication system issues a token - a digital proof that the user has successfully authenticated. That token is what grants access to applications, email, files, and services for the next several hours. And that token can be stolen, independently of the password and independently of the MFA challenge.

Token theft accounted for 31% of Microsoft 365 breaches in 2025, making it the primary attack vector - surpassing traditional credential compromise. Once a token is stolen, the attacker has what the system considers proof of a successful login. MFA worked as designed. The authentication record shows a legitimate sign-in. The attacker is inside, operating with the identity of a real user, without having needed their password.

This is the identity security problem that sits beyond the login screen - and it's the one most businesses haven't fully addressed.

 

## How Identity Attacks Are Moving Beyond Password Theft

Understanding the current attack methods matters because the defences follow from the methods. Here are the patterns most relevant to NZ businesses running Microsoft 365.

### Session and Token Theft

When a user successfully authenticates - username, password, MFA - the system issues an authentication token. This token functions as a temporary digital identity, telling connected services that the user has already been verified. It typically remains valid for hours and sometimes longer.

Attackers have developed effective methods for stealing these tokens. Adversary-in-the-Middle phishing - where a convincing fake website proxies the real authentication in real time - captures not just the credentials but the authentication token that follows the completed MFA challenge. The attacker receives the token. The user completes MFA, sees what appears to be a successful login, and moves on. The attacker uses the stolen token from a different location to access the same session.

Microsoft reported over 10,000 AiTM attacks per month targeting its users in 2024. A single phishing-as-a-service platform - Tycoon 2FA - accounted for roughly 62% of the phishing volume Microsoft blocked at its peak, including more than 30 million fraudulent emails in a single month. These aren't bespoke attacks by sophisticated actors. They're commercial products sold with customer support and subscription pricing.

The critical implication: these attacks succeed against MFA. Not by breaking it. By waiting for it to complete and stealing what it produces.

### MFA Fatigue

MFA fatigue - sometimes called push bombing - takes a different approach. An attacker who has obtained valid credentials (through phishing or breach data) uses them to trigger repeated authentication requests to the user's phone. The user receives a stream of MFA prompts they didn't initiate. Eventually - particularly late at night, or during a busy period, or after the prompts have continued long enough - the user approves one to make them stop.

The 2025 Verizon Data Breach Investigations Report documented a 217% year-over-year increase in MFA fatigue attacks. Microsoft documented 382,000 such attacks in a single year across its platforms.

The attack requires no technical sophistication. It exploits the gap between a security system and a human being operating under the assumption that the prompts are a system error.

### Helpdesk Impersonation and Account Recovery

The NCSC NZ's own reporting confirmed a pattern that Layer3's 2026 threat landscape analysis also documented: attackers are calling NZ IT helpdesks pretending to be staff. They use information gathered from LinkedIn, breach databases, and public sources to sound credible - knowing the employee's name, their manager, their role, sometimes details about recent projects - and requesting password resets or MFA changes.

Mandiant's M-Trends 2026 report specifically documents groups like UNC3944 - known as Scattered Spider - making helpdesk impersonation a systematic part of their methodology. They target the human process around identity, rather than the technical controls. Because account recovery is designed to help real users who are locked out, it can, if verification processes aren't sufficiently rigorous, also help attackers who are pretending to be those users.

Once a reset is granted, the MFA the business configured no longer protects the account. The attacker registers their own device. They control the identity.

### OAuth Application Abuse

Microsoft 365 allows users to connect third-party applications - tools for productivity, automation, document signing, scheduling - and grant them access to email, files, and calendar. This is legitimate and useful. It also creates an access pathway that persists beyond the user's awareness and, importantly, beyond their employment.

When a user grants an application OAuth access, that application receives tokens that function independently of the user's password and MFA. When the user leaves the organisation, the application connection often remains. The NCSC NZ specifically noted that attackers are attempting to register malicious applications and gain persistent access through OAuth grants - a pathway that survives password changes entirely.

The largest SaaS breach of 2025 began with a compromised third-party application. Attackers exploited OAuth tokens to access hundreds of downstream customer environments. The impact was described as ten times greater than direct infiltration would have produced.

### AI-Assisted Social Engineering

The NCSC's 2025 threat report noted that AI is enabling attackers to create personalised phishing, deepfakes, malicious code, and automated attacks at a pace and scale that wasn't previously possible. The 2024 Verizon DBIR reported a 900% year-over-year increase in deepfake file volume.

In the identity context, this matters most at the verification layer. UK NCSC and CISA guidance - published in response to high-profile helpdesk impersonation attacks including those against Marks & Spencer and Co-op - specifically addresses the challenge that deepfake voice tools now pose to phone-based identity verification. Guidance recommends moving to video verification with ID confirmation for credential reset requests, because voice alone is no longer a reliable verification method.

This isn't a theoretical future risk. It's informing current NCSC guidance because current attacks are using these techniques.

 

## Why MFA Still Matters - But Isn't the Entire Answer

MFA remains one of the most important security controls available to NZ businesses. Microsoft's data consistently shows that the overwhelming majority of compromised accounts did not have MFA enabled. Enabling MFA significantly raises the bar for the most common attack methods - basic credential theft, password spraying, and brute force attacks that rely on a stolen username and password being sufficient for access.

The attack methods described above don't change that. They demonstrate that attackers are operating in a more sophisticated environment and are specifically targeting the gaps that MFA doesn't address - the session after authentication, the social engineering around account recovery, the applications that retain access tokens independently of passwords.

The positioning that's accurate: MFA is one important control in a broader identity security strategy. It's not the destination.

Businesses that have deployed MFA and moved on have done something genuinely valuable. The question worth asking next is: what would an attacker who found MFA in place go after instead? And does the business have any visibility into whether that's happening?

 

## What Happens When an Attacker Takes Over an Identity?

To understand why identity security extends beyond the login, it helps to follow what an attacker who has successfully compromised an account can actually do with it.

An identity in a Microsoft 365 environment is connected to email, SharePoint, OneDrive, Teams, calendar, and any SaaS applications the user's account can access. The specific impact of a compromise depends entirely on what that identity can reach.

An employee account with standard access can provide an attacker with email history - including discussions about transactions, supplier relationships, and client information. It can provide access to files and documents stored in OneDrive and SharePoint sites the employee can view. It can provide the ability to send emails that appear to come from the employee, to internal colleagues and external contacts who will treat those emails as legitimate.

This last capability - the ability to impersonate the employee convincingly - is where identity compromise connects directly to financial fraud. Business email compromise, the NCSC's consistently high-loss incident category, typically involves an attacker who has access to an email account monitoring how the business communicates about financial transactions, then intervening at the right moment to redirect a payment. The attacker doesn't need privileged access. They need a standard account, patience, and the right timing.

An account with broader access - a finance role, an HR function, an IT administrator - provides proportionally greater reach. And a privileged account - Global Administrator, Security Administrator, Exchange Administrator - provides an attacker with access to the identity infrastructure itself.

The question isn't whether a compromised account always leads to the most severe possible outcome. It's whether the business understands what that account can access, and whether it would know if something unusual was happening with it.

 

## The Human Side of Identity Security

Modern identity attacks increasingly target people and the processes built around identity systems - not just the technical controls.

The helpdesk impersonation pattern illustrates this precisely. The attacker doesn't try to break the authentication system. They call the person responsible for resetting access and ask them to do it. They've gathered enough information to sound credible. They create urgency. They exploit the fact that the verification process, designed to help real users, may not have a sufficiently rigorous method for confirming that the person calling is actually who they say they are.

The MFA fatigue attack targets a different human instinct - the tendency to resolve an interruption. The technical control works as designed. The attacker relies on the human being more motivated to stop the prompts than to investigate their source.

This doesn't mean employees are doing something wrong. It means identity systems involve people at points that have operational logic - a user who can't access their account genuinely needs help. Authentication prompts sometimes do appear unexpectedly. These are the gaps that a well-resourced attacker will find and use.

The practical implication: identity security requires both strong technical controls and clear operational processes. Who can authorise a password reset? What verification is required before that reset happens? How does the business distinguish between a legitimate MFA prompt and an attack? These are operational questions as much as technical ones, and they require deliberate answers rather than assumptions.

 

## How Much Do You Actually Know About Your Identity Environment?

Most businesses know how many employees they have. The picture of their identity environment is often less complete than that suggests.

Consider the questions that require an active investigation rather than a quick answer:

How many accounts in your Microsoft 365 environment have Global Administrator or other privileged roles - and is each of those accounts actively used by someone who currently needs that level of access? Former IT staff sometimes retain privileged access after their role changes. IT providers sometimes retain admin access after a contract ends. Service accounts created for specific projects sometimes accumulate privileges that were never reviewed.

Which third-party applications currently have OAuth access to your Microsoft 365 environment, what permissions do they hold, and who connected them? The list may be longer than expected, and may include applications connected by staff who have since left the organisation.

Which guest accounts and external users currently have access to SharePoint sites, Teams channels, or shared resources - and is that access still appropriate? Guest access granted for a specific collaboration often persists long after the project concludes.

Which accounts have authentication methods that differ from the business's standard MFA policy - because an exception was created for a legacy system, or a particular user, or a specific application that doesn't support modern authentication?

What happened in your Entra ID sign-in logs last week? Were there sign-ins from unexpected locations? Account changes that weren't initiated by the account holder? Authentication events at unusual hours?

This isn't a hypothetical list of things to worry about. It's the identity layer of what our post on [Microsoft 365 security drift](https://blog.nsp.co.nz/microsoft-365-security-drift-nz-business) describes - the gradual accumulation of changes, exceptions, and forgotten access that means the identity environment today may look quite different from the one that was originally configured.

 

## Why Identity Monitoring Matters

There's an important limitation that BladeOne's 2026 analysis of Microsoft Entra ID documented: base Microsoft Entra ID - the Free tier included with most Microsoft 365 subscriptions - provides zero post-authentication attack detection. It monitors authentication events. It doesn't detect anomalous token behaviour, session hijacking, or unusual post-login activity.

Entra ID P2 - included with Microsoft 365 Business Premium - adds Identity Protection: risk-based detection of compromised sign-ins, unusual access patterns, and identity risk events. This is the Microsoft tooling that starts to address post-authentication monitoring.

But the tooling requires someone to be watching. Microsoft Entra generates sign-in risk alerts, impossible travel detections, and identity risk events. These alerts are information - they indicate that something unusual has happened. Acting on them requires someone to investigate: is this a genuine compromise, a staff member travelling, a legitimate new device? What did the account access during the session? Are there related events across other systems?

This is the same monitoring gap our post on [who is watching your cybersecurity](https://blog.nsp.co.nz/who-is-watching-your-cybersecurity-nz-mdr) describes, applied specifically to identity. The signals are there. Investigation is what turns them into action.

For NZ businesses running Microsoft 365, the practical implication is that identity monitoring - watching for the signals that suggest a compromise has occurred or is underway - is a function that requires dedicated attention. A suspicious sign-in at 3am from an IP address in a country the employee has never visited is worth investigating. A new OAuth application grant with broad permissions is worth reviewing. An authentication method change on an account that the account holder didn't initiate is worth immediate attention.

NSP's [Managed Detection and Response service](https://go.nsp.co.nz/managed-detection-and-response-for-nz-smes) monitors these identity signals continuously - correlating activity across endpoints, email, and Microsoft 365 identity to identify patterns that individual alerts might not make visible.

 

## Identity Security Is Prevention, Visibility, and Response

The architecture that addresses modern identity attacks operates across three connected functions.

**Prevention** - the controls that make compromise harder. MFA, critically including phishing-resistant methods like Microsoft Authenticator with number matching rather than simple push notifications where possible. Conditional Access policies that require device compliance and block access from high-risk locations. Privileged Identity Management that provides just-in-time admin access rather than standing privilege. Clear account recovery verification processes that don't rely solely on information an attacker could gather from social media and breach databases.

**Visibility** - the understanding of what the identity environment actually looks like. Who has privileged access, currently. Which applications have OAuth permissions, and what they can access. Which accounts are inactive or belong to former employees. Which guest accounts are still active. What the sign-in logs show for unusual patterns. This is the function that identity drift - the accumulation of changes, exceptions, and forgotten access over time - gradually erodes. Maintaining it requires active review rather than periodic assumption.

**Response** - the capability to act quickly when identity signals suggest a compromise. Isolating a suspicious session. Revoking tokens on a compromised account. Reviewing what the account accessed during the suspicious period. Understanding whether related activity suggests other accounts are affected. This requires both the monitoring to detect the signals and the process to respond to them.

These three functions together constitute identity security. Any one of them in isolation leaves meaningful gaps.

 

## The Questions Businesses Should Ask Beyond Passwords and MFA

These are leadership questions - worth asking directly rather than assuming the answers.

**Who currently has privileged access in our Microsoft 365 and Entra ID environment?** Not who should have it based on the original setup. Who actually has it today - including former IT providers, legacy accounts, and administrators whose roles may have changed.

**How does the business verify identity before resetting an account or changing authentication methods?** Does the verification process rely on information an attacker could plausibly have gathered? Is there a defined process, or does it vary depending on who handles the request?

**Which applications currently have OAuth access to our Microsoft 365 environment?** When was that list last reviewed? Does it include applications connected by staff who have since left?

**What Entra ID licence tier does the business have?** If it's the Free tier included with basic Microsoft 365 subscriptions, post-authentication attack detection is not available without an upgrade.

**When an unusual sign-in or identity risk event occurs, who sees it?** Who investigates? What's the process for determining whether it represents a genuine compromise?

**What would the business investigate if an employee account was reported as behaving unusually?** Who would look at the sign-in logs? Who would check what the account accessed? Who would review whether other accounts show related activity?

**When did the business last review its identity environment comprehensively?** Not just MFA coverage - the full picture of accounts, access, applications, and permissions.

 

## What the Attack Tells You About the Defence

Return to the methods described earlier. Attackers who find MFA in place move to the session after authentication - stealing tokens, intercepting authenticated connections. They move to the processes around authentication - impersonating employees to trigger resets, exploiting account recovery. They move to the applications that hold persistent access - OAuth grants that survive password changes and continue after an employee's departure.

These are not exotic, technically sophisticated attacks. The commercial phishing-as-a-service platforms that deliver AiTM attacks are subscription products with customer support. The helpdesk impersonation approach documented by Mandiant requires persistence and social skill, not technical capability. The NCSC's confirmation that this is happening in New Zealand removes any remaining ambiguity about whether this is a local concern.

The defence that addresses these attacks looks different from MFA configuration. It looks like understanding what the identity environment actually contains. It looks like monitoring for the signals that suggest something is wrong after the login has succeeded. It looks like having a clear, rigorous process for the moments where humans make decisions about identity - account recovery, authentication changes, application approvals. And it looks like knowing who would investigate and respond if those signals appeared.

If one employee identity in your business was compromised today - not through breaking MFA, but through one of the methods described above - the questions worth having answered in advance are: would you know? What would you check? How quickly could you contain it? And what does the answer tell you about whether your identity security extends beyond the login screen?

**[Book a Microsoft 365 identity security review with NSP →](https://go.nsp.co.nz/managed-detection-and-response-for-nz-smes)**

Or call us: **0508 010 101**

 

## Frequently Asked Questions About Identity Security Beyond MFA

**Is MFA no longer effective?**

MFA remains one of the most important security controls available to businesses. Microsoft's data consistently shows that the vast majority of compromised accounts didn't have MFA enabled. MFA effectively addresses basic credential theft, password spraying, and brute force attacks. What it doesn't address is everything that happens after a successful authentication - session tokens, social engineering around account recovery, OAuth application access. MFA is one important control in a broader identity security strategy, not the complete answer.

**What is MFA fatigue and how does it work?**

MFA fatigue - also called push bombing - is an attack where an attacker who has obtained valid credentials repeatedly triggers MFA prompts to the user's phone. The attacker relies on the user eventually approving a prompt to stop the interruptions. The 2025 Verizon DBIR documented a 217% year-over-year increase in this technique. The defence is moving from simple push-approval MFA to number-matching authentication, where the user must match a code displayed on the login screen rather than simply approving an unknown request.

**What is token theft and why does it bypass MFA?**

When a user successfully completes authentication - including MFA - the system issues an authentication token that grants access for a period of time. Token theft involves stealing this token before it's used or during an active session. Because the token represents proof of completed authentication, the attacker who holds it can access the session without needing the user's password or completing MFA. Token theft accounted for 31% of Microsoft 365 breaches in 2025 (Obsidian Security).

**What is helpdesk impersonation and how can businesses defend against it?**

Helpdesk impersonation involves an attacker contacting IT support, pretending to be a legitimate employee, and requesting a password reset or authentication change. Attackers gather convincing information from LinkedIn, breach databases, and public sources. The NCSC NZ confirmed this is an active attack method against NZ organisations. Defence involves rigorous verification processes for account recovery - specifically, processes that don't rely solely on information an attacker could plausibly know. NCSC and CISA guidance recommends moving toward video verification with ID for credential reset requests.

**What are OAuth permissions and why do they matter for identity security?**

When employees connect third-party applications to Microsoft 365 - tools for productivity, document signing, scheduling - those applications receive OAuth permissions that grant them access to email, files, or calendar. These permissions persist independently of the user's password and often survive the user leaving the organisation. An application with OAuth access that nobody has reviewed or revoked remains a potential access pathway. A review of which applications currently have access, and what permissions they hold, is part of a comprehensive identity security picture.

**How do I know if my Microsoft 365 accounts have been compromised?**

Signs to look for include sign-in activity from unexpected locations or devices, authentication method changes the account holder didn't initiate, new OAuth applications appearing in your tenant, email forwarding rules that weren't set up by the account holder, and unusual file access activity. Microsoft Entra ID provides sign-in logs and, with Entra ID P2, Identity Protection risk events. Our post on [how to know if your business has been breached](https://blog.nsp.co.nz/how-do-i-know-if-my-business-has-been-breached) covers the broader indicators in detail.

**What is Microsoft Entra ID P2 and does my business need it?**

Microsoft Entra ID P2 adds Identity Protection - risk-based detection of compromised sign-ins, unusual access patterns, and identity risk events. Base Entra ID (Free, included with basic Microsoft 365) provides zero post-authentication attack detection. Entra ID P1 is included with Microsoft 365 Business Premium and adds Conditional Access. P2 adds the behavioural detection that starts to address post-authentication attacks. For businesses handling sensitive client data or operating in high-risk environments, P2 capability is increasingly relevant.

[Book a Microsoft 365 identity security review with NSP →](https://go.nsp.co.nz/managed-detection-and-response-for-nz-smes)

#### CATEGORY

- [Cybersecurity (99)](https://blog.nsp.co.nz/tag/cybersecurity)
- [Digital transformation (37)](https://blog.nsp.co.nz/tag/digital-transformation)
- [Managed services (33)](https://blog.nsp.co.nz/tag/managed-services)
- [Awareness and education (23)](https://blog.nsp.co.nz/tag/awareness-and-education)
- [Cloud (23)](https://blog.nsp.co.nz/tag/cloud)
- [AI (20)](https://blog.nsp.co.nz/tag/ai)
- [Breach (17)](https://blog.nsp.co.nz/tag/breach)
- [IT Risk (17)](https://blog.nsp.co.nz/tag/it-risk)
- [modern workplace (12)](https://blog.nsp.co.nz/tag/modern-workplace)
- [Collaboration (11)](https://blog.nsp.co.nz/tag/collaboration)
- [Cyber Smart Week (11)](https://blog.nsp.co.nz/tag/cyber-smart-week)
- [Managed Detection & Response (MDR) (11)](https://blog.nsp.co.nz/tag/managed-detection-response-mdr)
- [Business strategy (9)](https://blog.nsp.co.nz/tag/business-strategy)
- [Culture (9)](https://blog.nsp.co.nz/tag/culture)
- [microsoft (9)](https://blog.nsp.co.nz/tag/microsoft)
- [Backup (8)](https://blog.nsp.co.nz/tag/backup)
- [Remote Workers (8)](https://blog.nsp.co.nz/tag/remote-workers)
- [copilot (7)](https://blog.nsp.co.nz/tag/copilot)
- [Cyber Insurance (6)](https://blog.nsp.co.nz/tag/cyber-insurance)
- [Future of work (6)](https://blog.nsp.co.nz/tag/future-of-work)
- [network performance (6)](https://blog.nsp.co.nz/tag/network-performance)
- [Vulnerability Assessment (5)](https://blog.nsp.co.nz/tag/vulnerability-assessment)
- [Microsoft Teams (4)](https://blog.nsp.co.nz/tag/microsoft-teams)
- [vCISO (4)](https://blog.nsp.co.nz/tag/vciso)
- [0365 (3)](https://blog.nsp.co.nz/tag/0365)
- [Governance (3)](https://blog.nsp.co.nz/tag/governance)
- [IT budget (3)](https://blog.nsp.co.nz/tag/it-budget)
- [Legal Industry (3)](https://blog.nsp.co.nz/tag/legal-industry)
- [Best Practice (2)](https://blog.nsp.co.nz/tag/best-practice)
- [Construction Industry (2)](https://blog.nsp.co.nz/tag/construction-industry)
- [Penetration Testing (2)](https://blog.nsp.co.nz/tag/penetration-testing)
- [Tabletop Exercise (2)](https://blog.nsp.co.nz/tag/tabletop-exercise)
- [health IT consultant (2)](https://blog.nsp.co.nz/tag/health-it-consultant)
- [Healthcare (1)](https://blog.nsp.co.nz/tag/healthcare)

see all

#### RECENT POST

[![](https://blog.nsp.co.nz/hubfs/NZ%20business%20leader%20reviewing%20Microsoft%20Entra%20ID%20identity%20security%20dashboard%20on%20laptop%2c%20representing%20identity%20security%20monitoring%20beyond%20MFA%20for%20New%20Zealand%20organisations.png)](https://blog.nsp.co.nz/identity-security-beyond-mfa-nz-busines)

[Identity Security Beyond MFA | NSP](https://blog.nsp.co.nz/identity-security-beyond-mfa-nz-busines)

 27 Sept 2026

[![](https://blog.nsp.co.nz/hubfs/Christchurch%20construction%20project%20site%20at%20dusk%20with%20modern%20commercial%20building%20under%20construction%2c%20representing%20cybersecurity%20risk%20for%20Canterbury%20construction%20and%20engineering%20firms.png)](https://blog.nsp.co.nz/christchurch-construction-engineering-cybersecurity-monitoring-mdr)

[Christchurch Construction Cyber Security: The Monitoring Gap | NSP](https://blog.nsp.co.nz/christchurch-construction-engineering-cybersecurity-monitoring-mdr)

 23 Sept 2026

[![](https://blog.nsp.co.nz/hubfs/Healthcare%20professional%20at%20a%20clinical%20workstation%20reviewing%20a%20security%20alert%20notification%2c%20representing%20cybersecurity%20monitoring%20for%20New%20Zealand%20healthcare%20organisations.png)](https://blog.nsp.co.nz/nz-healthcare-cybersecurity-monitoring-mdr-2026)

[Why NZ Healthcare Needs 24/7 Security Monitoring in 2026 | NSP](https://blog.nsp.co.nz/nz-healthcare-cybersecurity-monitoring-mdr-2026)

 23 Sept 2026

[![](https://blog.nsp.co.nz/hubfs/Auckland%20city%20skyline%20at%20night%20viewed%20from%20a%20dark%20office%2c%20representing%20cybersecurity%20monitoring%20gaps%20for%20Auckland%20businesses%20outside%20business%20hours.png)](https://blog.nsp.co.nz/auckland-after-hours-cybersecurity-monitoring-mdr)

[When Auckland Closes for the Night, Attackers Don't | MDR | NSP](https://blog.nsp.co.nz/auckland-after-hours-cybersecurity-monitoring-mdr)

 23 Sept 2026

### Let’s stay in touch!

Enter your details below to stay up-to-date with the latest IT solutions and security measures.

[![NSP\_Logo\_footer](https://blog.nsp.co.nz/hs-fs/hubfs/NSP%20assets%202024/Images/NSP_Logo_footer.png?width=170&height=85&name=NSP_Logo_footer.png)](https://nsp.co.nz/)

A trusted technology partner for NZ SMEs. Building secure, scalable technology solutions for more than 20 years

##### Useful Links

- [About us](https://nsp.co.nz/about-us/)
- [Procurement](https://savvi.net.nz/)
- [Cybersecurity](https://nsp.co.nz/cybersecurity/)
- [Managed Services](https://nsp.co.nz/managed-services/)
- [Cloud](https://nsp.co.nz/cloud/)
- [Contact us](https://nsp.co.nz/contact-us/)

##### Contact

Unit 1, 13 Farnham Street Parnell, Auckland 1052, NZ

- [0508 010 101](tele:0508%20010%20101)
- [info@nsp.co.nz](mailto:info@nsp.co.nz)

- <https://www.linkedin.com/company/network-service-providers-nsp-/>
- <https://vimeo.com/nspnz>
- <https://www.facebook.com/NetworkServiceProviders/>

Copyright © 2026 NSP - All rights reserved

- [Terms & Conditions](https://blog.nsp.co.nz/hubfs/NSP%20Terms%20and%20conditions/NSP%20Terms%20%26%20Conditions%202021.pdf)
- [Privacy Policy](https://nsp.co.nz/privacy-policy/)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "NSP Marketing",
    "url" : "https://blog.nsp.co.nz/author/nsp-marketing"
  },
  "dateModified" : "2026-09-27T21:00:00.243Z",
  "datePublished" : "2026-09-27T21:00:00.000Z",
  "headline" : "Identity Security Beyond MFA | NSP",
  "image" : [ "https://blog.nsp.co.nz/hubfs/NZ%20business%20leader%20reviewing%20Microsoft%20Entra%20ID%20identity%20security%20dashboard%20on%20laptop%2c%20representing%20identity%20security%20monitoring%20beyond%20MFA%20for%20New%20Zealand%20organisations.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.nsp.co.nz/identity-security-beyond-mfa-nz-busines",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.nsp.co.nz/hubfs/NSP_Logo_Primary%20logo_CMYK_1.png"
    },
    "name" : "Network Service Providers Ltd"
  }
}
```