How to Defeat AiTM Phishing With Compliant-Device and Phishing-Resistant MFA Policies
Retrospective: this article looks back at events from July 2022, written in 2026 with the benefit of hindsight.
Adversary-in-the-middle phishing steals session cookies after users complete MFA. Two controls stop it: phishing-resistant authentication and compliant-device requirements. Here is how to deploy both in Entra ID.
Control 1: Phishing-resistant MFA
Passkeys, FIDO2 security keys, Windows Hello for Business and certificate-based authentication are bound to the legitimate site's origin. A proxy can't relay them.
- Enable passkeys (FIDO2) and Windows Hello for Business in the authentication methods policy.
- Create a Conditional Access policy using authentication strength: Phishing-resistant MFA.
- Apply it first to administrators, then executives, finance and other high-risk users.
- Expand to all users as registration grows.
Control 2: Require compliant or hybrid-joined devices
If access requires a device that's managed and compliant, a stolen cookie replayed from the attacker's machine fails.
- Enroll devices in Intune with compliance policies.
- Create a Conditional Access policy requiring Require device to be marked as compliant (or Microsoft Entra hybrid joined) for Office 365 and other sensitive apps.
- For personal devices, use app protection policies and limit to web access with session controls.
Supporting controls
- Token protection (where supported) binds sessions to devices.
- Defender for Office 365 Safe Links and anti-phishing policies reduce delivery of phishing emails.
- Identity Protection risk policies respond to "attacker in the middle" and anomalous token detections.
- Continuous Access Evaluation speeds up revocation.
Rollout tips
- Start in report-only mode and review sign-in logs.
- Give users a clear registration path and help desk support.
Verify
Test with a controlled phishing simulation using an AiTM-capable framework in a lab, confirming sign-in fails from unmanaged devices.