Identity security: defending against MFA fatigue and token theft
For Microsoft 365 and Entra ID administrators, MSP technicians and service desk level 3 staff who look after sign-in security for an organization. Prerequisites: 'MFA prompts: when to approve and when to deny' (the user's side of push prompts) and 'Conditional Access concepts'. This course is the admin side: how push bombing and token theft get past ordinary MFA, which Authenticator settings and phishing-resistant methods close the gap (using CISA's MFA fact sheets), how to pilot Conditional Access token protection without breaking apps, how to spot push bombing and token replay in sign-in logs and ID Protection, and how to evict an attacker who holds a stolen session. Examples use Microsoft Entra ID; several features need Entra ID P1 or P2 licences. Your organization's incident runbook decides who may disable accounts and change policies.
- Level
- Intermediate
- Length
- About 125 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify how MFA fatigue (push bombing) and token theft attacks work and which defence each one gets past
- Choose MFA methods and Authenticator settings that resist push bombing and phishing, including number matching and phishing-resistant authentication strengths
- Configure a Conditional Access token protection policy in report-only mode with the right apps, platforms and exclusions
- Investigate sign-in logs and risk detections for evidence of push bombing and token replay
- Respond to a stolen session: disable the account, revoke sessions, reset credentials and remove attacker persistence
Course outline
- 1.How MFA fatigue and token theft attacks work, and which defence each gets pastLesson · 18 min
- 2.Choose MFA methods and Authenticator settings that resist push bombing and phishingLesson · 25 min
- 3.Configure a Conditional Access token protection policy in report-only modeLesson · 22 min
- 4.Investigate sign-in logs and risk detections for push bombing and token replayLesson · 22 min
- 5.Respond to a stolen session: disable, revoke sessions, reset credentials and remove persistenceLesson · 20 min
- 6.Identity security: defending against MFA fatigue and token theft: knowledge checkKnowledge check · 15 questions
- 7.Identity security: defending against MFA fatigue and token theft: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- CISA: Implementing Phishing-Resistant MFA (fact sheet, October 2022)
- CISA: Implementing Number Matching in MFA Applications (fact sheet, October 2022)
- Microsoft Learn: How number matching works in multifactor authentication push notifications for Authenticator
- Microsoft Learn: Use additional context in Authenticator notifications
- Microsoft Learn: Configure Microsoft Entra multifactor authentication settings (report suspicious activity)
- Microsoft Learn: Conditional Access authentication strengths
- Microsoft Learn: Token Protection in Microsoft Entra Conditional Access
- Microsoft Learn: Token Protection deployment guide - Windows
- Microsoft Learn: Protecting tokens in Microsoft Entra ID
- Microsoft Learn: What are risk detections? (Microsoft Entra ID Protection)
- Microsoft Learn: Revoke user access in Microsoft Entra ID
- Microsoft Security Blog: Token tactics: How to prevent, detect, and respond to cloud token theft (November 2022)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.