Scenario library / Identity

Cloud Identity Takeover via MFA Fatigue: a tabletop exercise scenario

Repeated push prompts land on a privileged administrator overnight. One is approved. Logs later show new tenant app consents and mailbox rules.

60–90 min · Technical + executive sponsor

Abstract graphic representing cloud identity takeover via mfa fatigue

What this is modelled on

Modelled on intrusions where attackers spam push notifications until a privileged user accepts one, then consent malicious tenant applications, create inbox rules and register their own authentication methods to hold access.

Why it matters

Identity compromise gives an attacker legitimate sessions, not malware. Recovery means breaking your own trust model while people still need to work.

Exercise objectives

  • Test privileged access recovery and token revocation sequencing
  • Confirm who can force a tenant-wide credential reset
  • Validate detection coverage for consent grants and rule creation
  • Rehearse communications when staff are locked out mid-day

Decision points tested

  • Immediate mass revocation versus targeted containment
  • Whether to disable legacy authentication and app consent now
  • Forensic scope and evidence preservation in cloud logs
  • Staff communication for a forced reset

Sample inject timeline

  1. T+0

    Suspicious sign-in

    A privileged sign-in appears from an unfamiliar country with a successful MFA approval.

  2. T+20

    Persistence found

    A new enterprise application has mail-read consent and a forwarding rule exists on the finance mailbox.

  3. T+40

    Second account

    A second administrator account shows a newly registered authenticator.

  4. T+60

    Business friction

    Leadership pushes back on a tenant-wide reset during a trading day.

What the after-action report should capture

  • Privileged account inventory accuracy
  • Detection gaps for consent and rule events
  • Recovery runbook completeness
  • Conditional access hardening actions

Run this scenario with your team

Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.