Compliance

ITDR vs MFA vs Conditional Access: Stopping BEC at SMBs

ITDR vs MFA vs Conditional Access: Stopping BEC at SMBs

Know what attackers see before they do. See a sample Radar scan report →

If you're an IT admin who deployed MFA and figured business email compromise (BEC) was a solved problem, there's an active campaign right now proving otherwise.

According to The Hacker News, attackers are running a US-focused phishing campaign that specifically targets C-suite executives, steals authenticated Microsoft 365 sessions, and then deploys RMM tools to maintain remote access. The important detail: this attack doesn't need your password, and it doesn't need to beat your MFA prompt. It steals the session token after authentication has already happened, which means MFA — the control most small businesses lean on hardest — never gets a chance to stop it.

This is exactly the gap raised in the Reddit threads that inspired this post: teams running ITDR tools still got hit with BEC, and Microsoft has quietly shifted MFA registration behavior without much warning. The tools were in place. The breach still happened. So what actually would have caught it?

Why MFA Alone Isn't Enough Anymore

MFA is designed to stop credential theft — someone guessing or phishing your password. It was never designed to stop session hijacking, where an attacker steals the cookie or token generated after you've already logged in and passed MFA. Once that token is stolen, the attacker looks like you to Microsoft 365. No second prompt required.

We've written before about how device code phishing bypasses MFA in a similar way — tricking users into approving a legitimate-looking auth flow that hands over a valid session. Session-token theft campaigns are just the next evolution of the same core problem: MFA protects the login, not everything that happens after.

Where ITDR Fits — and Where It Falls Short

Identity Threat Detection and Response (ITDR) tools are supposed to catch anomalous identity behavior: impossible travel logins, new device fingerprints, unusual mailbox rule creation, or a session suddenly being used from a different geography. In theory, ITDR is exactly the layer that should catch a stolen session in use.

In practice, according to the same Reddit discussion referenced in this post, two separate BEC incidents went completely undetected despite ITDR being deployed. That's not a knock on ITDR as a category — it's a reminder that ITDR is a detection layer, not a prevention layer. It has to be tuned, monitored, and alerted on by a human who actually acts on the alert. A tool sitting quietly in a dashboard that nobody checks is functionally the same as no tool at all.

That undetected-for-weeks pattern isn't unique to small business M365 environments either. According to The Hacker News, a credential-based data theft incident against French tax systems using stolen staff passwords went undetected for seven weeks — in an environment that presumably had some level of monitoring in place. Detection tools only work if someone is watching the output and knows what to do with it.

Where Conditional Access Actually Closes the Gap

This is where Conditional Access earns its place. Unlike ITDR, which mostly detects and alerts, Conditional Access can actively block based on conditions: device compliance, location, sign-in risk level, and session lifetime. Set correctly, Conditional Access policies can force re-authentication on risky sign-ins, restrict access to managed devices only, and shorten how long a stolen session token is actually useful before it expires.

If you haven't reviewed your Conditional Access setup recently, our guide on Conditional Access policy setup order for small businesses walks through the sequence that actually matters — location-based restrictions and device compliance first, then risk-based sign-in policies, then session controls. Order matters because misconfigured policies can lock out legitimate users or leave gaps attackers exploit.

The Real Answer: Layers, Not a Single Tool

None of these controls alone stops the campaign described above. MFA stops credential theft but not session hijacking. ITDR can detect the hijack — if it's monitored and tuned. Conditional Access can limit the blast radius by restricting where and how sessions are used. Together, they cover more of the attack chain than any single control.

If your M365 environment has had login anomalies lately, it's also worth reviewing our broader breakdown of Microsoft 365 login attacks and the controls that actually stop them — it covers additional configuration steps beyond what's in this post.

Take Action

The uncomfortable truth is that most small businesses find out their identity controls have gaps only after an incident, not before. Proactive scanning catches misconfigurations, exposed sessions, and weak Conditional Access policies before an attacker does. Oscar Six Security's Radar scan is a $99 way to get a clear picture of where your identity and email security actually stand — no long contracts, no enterprise sales cycle. Check it out at our solutions page.

Focus Forward. We've Got Your Six.

Frequently Asked Questions

Can business email compromise happen even with MFA enabled?

Yes. Attackers increasingly use session hijacking to steal authentication tokens after MFA has already been completed, meaning they never need to beat the MFA prompt itself. This is exactly the technique used in the active M365 campaign covered by The Hacker News.

Does ITDR stop business email compromise on its own?

No. ITDR detects suspicious identity behavior but doesn't prevent it, and it only works if alerts are actively monitored and acted on. Multiple documented BEC incidents occurred despite ITDR being deployed simply because the alerts weren't caught in time.

What's the difference between MFA and Conditional Access?

MFA verifies identity at login with a second factor, while Conditional Access enforces ongoing rules about device compliance, location, and session risk even after login. Conditional Access can limit how long a stolen session stays useful, which MFA cannot do.

How do I know if my Microsoft 365 environment is vulnerable to session hijacking?

Review your Conditional Access policies for session lifetime controls, check ITDR or sign-in logs for anomalous locations or devices, and confirm MFA registration settings haven't been silently reset. A Radar scan from Oscar Six Security for $99 can help identify these misconfigurations quickly.

What tool should a small business use to detect BEC attempts?

No single tool fully covers business email compromise; effective protection combines MFA, Conditional Access, and monitored ITDR alerts. Small businesses without a dedicated security team should also consider periodic external scans, like Oscar Six Radar, to catch gaps between these layers.

Find out what's exposed. Radar scans your external attack surface and shows you exactly what needs fixing. See a sample report →