How to Find Remote Access Accounts That Bypass MFA
Retrospective: this article looks back at events from May 2021, written in 2026 with the benefit of hindsight.
Colonial Pipeline and Change Healthcare were both breached through remote access accounts without MFA. Here is how to find accounts and access paths that bypass MFA in your environment.
Step 1: List every remote access path
- VPNs and remote access gateways (Fortinet, Cisco, Palo Alto, Citrix, Ivanti and others).
- RDP gateways and jump servers.
- Cloud admin portals and SaaS applications.
- Vendor remote support tools.
- Exposed services such as SSH or RDP directly on servers.
Step 2: Check how each authenticates
The best pattern is authentication through Entra ID (SAML or RADIUS via NPS extension), so Conditional Access and MFA apply. Gateways using local accounts or LDAP-only authentication are the usual gaps.
Step 3: Find accounts without MFA
- Entra ID: sign-in logs filtered for
AuthenticationRequirement == singleFactorAuthenticationwith successful results show where MFA isn't applied. - Authentication methods registration report: users with no MFA method registered.
- Gateway local accounts: review directly on each device.
SigninLogs
| where ResultType == "0" and AuthenticationRequirement == "singleFactorAuthentication"
| summarize Count = count() by AppDisplayName, UserPrincipalName
| sort by Count desc
Step 4: Find dormant accounts
Accounts with no sign-in for 90 days — in Entra ID, Active Directory and on gateways. Disable them, then delete after a waiting period.
Step 5: Close the gaps
- Integrate gateways with Entra ID for MFA.
- Remove local accounts except documented break-glass.
- Block legacy authentication.
Verify
Repeat monthly; the single-factor list should contain only documented exceptions.
- Colonial Pipeline (May 2021): One Legacy VPN Password Without MFA Incident Teardowns
- Detecting VPN Logins Without MFA: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Colonial Pipeline and the Business Case for MFA on Everything CIO Briefings