How to Eliminate Legacy Authentication Risks

TL;DR
Disable legacy authentication protocols because they let attackers test stolen or predictable passwords without facing multifactor authentication. Microsoftβs data showed that more than 99 percent of compromised enterprise accounts lacked MFA, while password spraying and credential replay relied overwhelmingly on protocols such as IMAP, SMTP, POP, MAPI, and Exchange Web Services.
Transcript
Excuse me. Mic check. Yes. Right on. Excuse me. Hey, you're still here. I'm amazed. Um, thank you for, uh, thank you for coming on Friday morning after the bash and, uh, you know, making it all the way here. Uh, my name is Alex Weinert. I am the Director of Identity Security for Microsoft, so kind of in a nutshell, my team is responsible for trying... Read More
Key Insights
- Multifactor authentication is a decisive protective control because 99.99 percent of approximately 1.2 million compromised enterprise accounts observed in one month did not have MFA. The data indicates that MFA could have prevented the vast majority of those account compromises.
- MFA adoption was limited across the observed global user population because only 11 percent of users received any token with a strong-authentication claim during January 2020. Even a single strong-authenticated task or device counted toward that relatively low adoption figure.
- Legacy authentication consists of older protocols that do not permit an interactive sign-in conversation. Unlike OAuth-based flows, they cannot insert an MFA challenge, evaluate device health, or apply other contextual checks while the user is authenticating.
- Password spraying works by testing a small group of statistically probable passwords against a large collection of usernames. Typical campaigns tested roughly 10 to 20 passwords and achieved about a 1 percent success rate, using predictable choices such as QWERTY, ILoveYou, and password123.
- Legacy protocols were the dominant channel for password spraying because 99.7 percent of the observed spray attacks used protocols such as IMAP and SMTP. Existing attack tools make these attempts easy to automate, and attackers continue using techniques that reliably produce compromised accounts.
- Credential replay exploits username and password pairs obtained from previous breaches by testing them against another system. The attack succeeds when people reuse credentials, a behavior Microsoft observed among about 60 percent of users, including reuse of enterprise credentials in non-enterprise environments.
- SMTP, IMAP, and POP enablement is associated with a substantially higher probability of account compromise. These protocols attract attackers because they accept passwords, are supported by established cracking tools, and prevent defenders from enforcing multifactor authentication during the sign-in attempt.
- Complete remediation requires finding the final legacy dependencies because identifying the exact client, machine, and user behind an older protocol can be difficult. Closing most access paths is insufficient when attackers can deliberately target the small remainder that still accepts password-only authentication.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: Why is legacy authentication a security risk?
Legacy authentication is risky because older protocols cannot conduct an interactive sign-in exchange. Defenders therefore cannot insert a multifactor authentication challenge, check device health, or apply similar contextual controls during authentication. Attackers favor protocols such as IMAP, SMTP, POP, MAPI, and Exchange Web Services because they can repeatedly test passwords while avoiding protections available through modern authentication flows.
Q: How does multifactor authentication prevent account compromise?
Multifactor authentication requires a strong authentication step beyond the password, preventing a stolen or correctly guessed password from being sufficient by itself. Microsoft observed approximately 1.2 million compromised enterprise accounts in one month, and 99.99 percent did not have MFA. Based on that observation, MFA would have prevented the vast majority of those compromises.
Q: How common was MFA adoption in Microsoft's data?
Only 11 percent of users across the overall observed population received any token containing a strong-authentication claim during January 2020. The measurement was broad: a user counted even if strong authentication appeared only once, for one task, on one unusual device, through a federation server, or through Microsoftβs MFA service. The figure therefore showed limited adoption despite MFAβs protective value.
Q: How does a password spray attack work?
A password spray attack starts with a large collection of usernames and tests a small set of statistically probable passwords against them. Typical attacks used approximately 10 to 20 passwords and achieved around a 1 percent success rate. Common guesses included QWERTY, ILoveYou, password123, and 123456, allowing attackers to compromise accounts without repeatedly targeting one user.
Q: Why do password spray attacks use legacy protocols?
Password spraying relies heavily on legacy protocols because they accept password-based authentication without supporting interactive MFA challenges. Microsoftβs analysis found that 99.7 percent of observed password-spray attacks used legacy authentication, including IMAP and SMTP. Attackers also have established mail-cracking tools that automate common-password testing and can adapt guesses to an organizationβs known password-composition rules.
Q: What is a credential replay attack?
A credential replay attack takes username and password pairs exposed in an earlier breach and tests them against another service. A successful sign-in suggests that the person reused the same credentials across systems. Microsoftβs data indicated that about 60 percent of users reused passwords, and enterprise usernames and passwords were sometimes reused in non-enterprise environments, creating opportunities for replay.
Q: Which protocols were associated with credential attacks?
Observed credential attacks concentrated on older authentication protocols. Password spraying commonly used IMAP and SMTP, while replay activity used IMAP, SMTP, Exchange Web Services, Autodiscover, POP, and MAPI. The attacks were not primarily appearing through OAuth or SAML. These older access paths were attractive because they let attackers test credentials without encountering interactive multifactor authentication enforcement.
Q: How should enterprises address remaining legacy authentication dependencies?
Enterprises should identify and remove every remaining dependency on legacy authentication instead of assuming that closing most paths is enough. The final portion is difficult because defenders may struggle to determine which client, user, or machine is generating older protocol traffic. Attackers can target whatever remains, so remediation must account for hidden technical debt and applications that still require password-only access.
Summary & Key Takeaways
-
Legacy authentication is a major obstacle to effective multifactor authentication because older protocols cannot support interactive sign-in challenges. Protocols such as IMAP, SMTP, POP, MAPI, and Exchange Web Services let attackers test credentials without encountering MFA, device-health checks, or the richer controls available through modern authentication methods such as OAuth.
-
Microsoft processed about 30 billion sign-in events daily and observed roughly 1.2 million compromised enterprise accounts in a month. More than 99 percent of those accounts lacked MFA, yet only 11 percent of users received any token containing a strong-authentication claim during January 2020, revealing a substantial gap between protection and adoption.
-
Password spraying and credential replay each accounted for roughly 40 percent of observed attacks. About 99.7 percent of password-spray activity used legacy authentication, while replay attacks also concentrated on older protocols. Enterprises must identify every remaining dependency because attackers can exploit the small portion of legacy access left after an otherwise extensive remediation effort.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator