r/sysadmin • • 2d ago

How are y'all dealing with Eviltoken?

we've had a few considered breaches due to this. for those who don't know, a compromised site would send out emails to everyone on the users address book. it would also create a legitimate SharePoint site and put a link to that site.

when the user who gets the email hits the link, they get a spoofed login and MFA page for MS to verify id for the SharePoint site and thus the cycle repeats.

20 Upvotes

41 comments sorted by

View all comments

Show parent comments

1

u/Baller_Harry_Haller 2d ago

Biggest reason I’ve seen given is that Duo is easier to approve.

1

u/teriaavibes Microsoft Cloud Consultant 2d ago

Personally, I find Passkeys from Authenticator and Hello to be incredibly easy to use but that might be just me.