Skip to content

Identity security: defending against MFA fatigue and token theft

For Microsoft 365 and Entra ID administrators, MSP technicians and service desk level 3 staff who look after sign-in security for an organization. Prerequisites: 'MFA prompts: when to approve and when to deny' (the user's side of push prompts) and 'Conditional Access concepts'. This course is the admin side: how push bombing and token theft get past ordinary MFA, which Authenticator settings and phishing-resistant methods close the gap (using CISA's MFA fact sheets), how to pilot Conditional Access token protection without breaking apps, how to spot push bombing and token replay in sign-in logs and ID Protection, and how to evict an attacker who holds a stolen session. Examples use Microsoft Entra ID; several features need Entra ID P1 or P2 licences. Your organization's incident runbook decides who may disable accounts and change policies.

Level
Intermediate
Length
About 125 minutes
Contents
5 lessons · final exam
Status
Published · updated 10 Oct 2026

Skills you'll practise

  • Identify how MFA fatigue (push bombing) and token theft attacks work and which defence each one gets past
  • Choose MFA methods and Authenticator settings that resist push bombing and phishing, including number matching and phishing-resistant authentication strengths
  • Configure a Conditional Access token protection policy in report-only mode with the right apps, platforms and exclusions
  • Investigate sign-in logs and risk detections for evidence of push bombing and token replay
  • Respond to a stolen session: disable the account, revoke sessions, reset credentials and remove attacker persistence

Course outline

  1. 1.How MFA fatigue and token theft attacks work, and which defence each gets pastLesson · 18 min
  2. 2.Choose MFA methods and Authenticator settings that resist push bombing and phishingLesson · 25 min
  3. 3.Configure a Conditional Access token protection policy in report-only modeLesson · 22 min
  4. 4.Investigate sign-in logs and risk detections for push bombing and token replayLesson · 22 min
  5. 5.Respond to a stolen session: disable, revoke sessions, reset credentials and remove persistenceLesson · 20 min
  6. 6.Identity security: defending against MFA fatigue and token theft: knowledge checkKnowledge check · 15 questions
  7. 7.Identity security: defending against MFA fatigue and token theft: practical exerciseKnowledge check · 1 question
  8. 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.