Sprinter Voice: Addressing the Gaps in Your Multi‑Factor Security Policy

April 30, 20264 min read

Sprinter VoIP

Vishing phone scam photo of man with phone at computer

Addressing the Gaps in Your Multi‑Factor Security Policy

April 30, 2026 – By Darrick Hartman, Strategy & Alignment

You’ve enabled multi‑factor authentication in Microsoft 365. That’s a solid move and you’re already ahead of many organizations.

So, you’re covered now. Right?

Not always.

MFA is one of the best security tools we have, but it only works when it’s implemented fully and consistently. We regularly see environments where MFA is technically “on,” yet attackers still get in. Not by breaking MFA, but by quietly stepping around it.

Let’s talk through where that happens and how to fix it.

A Real‑World Example of MFA Working… and Still Losing

A few months ago, we helped review an environment after a suspicious sign‑in alert. The organization had MFA enabled across Microsoft 365 and felt confident that account compromises were unlikely.

The attacker never touched MFA.

Instead, they used a password spray attack against legacy email protocols that were still enabled. IMAP accepted the username and password without ever prompting for a second factor. Once inside, access looked legitimate. No alerts fired. Everything appeared normal.

By the time unusual behavior was noticed, the attacker had already accessed mailboxes.

From the outside, it looked like MFA had failed. In reality, MFA was never even invited to the party.

This is a very common pattern.

MFA Is Only as Strong as the Authentication It Protects

One of the biggest gaps we see is legacy authentication still enabled alongside modern MFA policies. Protocols like POP, IMAP, and SMTP were created long before MFA existed and simply do not support it.

If those protocols are left on, attackers don’t need to work around MFA. They just bypass it.

Modern authentication exists specifically to close this gap. If you’re using Microsoft 365 or Google Workspace and legacy protocols are still enabled, you’re protecting the front door while leaving a side entrance wide open.

Not All MFA Methods Are Equal

Another common misconception is that having any second factor automatically means strong protection.

SMS‑based MFA is still widely used, but it’s also one of the easiest methods to defeat. SIM swapping, cloned numbers, and proxy‑based phishing attacks all target text message codes successfully.

If SMS is still your primary method, this is your friendly “we should talk” moment.

Stronger options include phishing‑resistant authenticator methods, hardware security keys, or MFA systems that validate the sign‑in itself instead of just asking users to approve a push.

The goal is confidence, not inconvenience.

Conditional Access: Quiet but Powerful

Conditional access is one of the most effective and underused tools in Microsoft 365 security. It adds context to sign‑ins without adding friction for users.

That might mean restricting access to certain geographic regions or requiring a known, compliant device before access is granted. For most users, nothing changes. For attackers, everything does.

When attackers suddenly can’t log in from overseas infrastructure or unknown devices, attempts stop very quickly.

MFA Should Not Stop at the Cloud

Cloud accounts often get the most attention, but administrative access inside your environment deserves equal care.

We still see admin accounts without MFA because they are “needed in emergencies” or “just in case.” Unfortunately, attackers love those accounts too.

At a minimum, administrator access should require MFA. A stronger approach is just‑in‑time access, where admin privileges are granted only when needed, logged, and tied to a reason.

And those old break‑glass accounts with no MFA? They should exist only as a last‑ditch safety measure and be tightly monitored, not quietly forgotten.

Security Breaks at the Weakest Link

Most breaches don’t start with a dramatic exploit. They start with a small exception that was never revisited.

An old protocol. A weak MFA method. An admin account that felt harmless.

MFA is incredibly effective when it’s implemented thoughtfully and end‑to‑end. It’s far less effective when exceptions pile up quietly in the background.

Let’s Make Sure Yours Holds Up

If you’re not completely sure how MFA is enforced across your environment, or you suspect there may be a few “we’ll fix that later” settings still in place, you’re not alone.

At Sprinter, we help organizations look at MFA the way attackers do, then remove the paths they rely on most.

Give us a call or reach out. We’re always happy to walk through what strong, modern MFA should really look like for your organization.

Schedule an appointment or call (715) 551-6464.

Back to Blog