021 519 21 27
Blog · Security

Two-factor authentication is no longer enough: 5 blind spots to know

By Ricardo Da Silva, RSCOM · 10 October 2026

Two-factor authentication (MFA) is essential: without it, a single stolen password opens everything. But attackers have adapted. Many companies hit by ransomware had MFA switched on. The problem is not MFA itself, but what it does not cover. Here are the five most common blind spots.

1. Notification “fatigue”

The attacker knows the password and triggers dozens of approval requests on the victim’s phone, often at night. Out of weariness or by mistake, someone ends up tapping “Approve”.

The fix: require number matching (enabled by default in Microsoft Authenticator) and teach the team that a request they did not trigger themselves must be denied and reported.

2. Relay phishing sites

A link leads to a perfect copy of the Microsoft 365 sign-in page. The victim types their password and their code; the fake site passes them on live to the real service and grabs the open session. MFA worked… for the attacker.

The fix: phishing-resistant methods (FIDO2 security keys, passkeys, Windows Hello for Business), at least for administrator and management accounts, plus an anti-phishing filter on e-mail.

3. Session (cookie) theft

Malware installed on a computer steals the “tokens” that keep the user signed in. No password or code needed any more: the attacker reuses the session as it is.

The fix: a modern antivirus (EDR) on every computer, sensible session lifetimes and, with Microsoft Entra ID P1, access restricted to managed, compliant devices.

4. Forgotten accounts and access

A former employee, a test account, a shared mailbox with a password, an old e-mail protocol still enabled, a supplier’s access never removed: a single account without MFA is enough.

The fix: an account review twice a year, a systematic leaver process and blocking legacy sign-in methods. See the 7 essential Microsoft 365 settings.

5. MFA… on e-mail only

Often Microsoft 365 is protected, but not remote access (VPN, remote desktop), the firewall, the NAS, the company’s e-banking or the online business software.

The fix: list all access from the Internet and enable MFA wherever possible; close what is not needed (for example remote desktop exposed directly to the Internet).

Checklist in short

Need help? We support SMEs, practices and individuals in French-speaking Switzerland. Discover our Cybersecurity service (page in French) or call us on +41 21 519 21 27.

☕ New business customers: the first meeting is on us — a coffee and a free IT review, with no obligation.

Contact us 021 519 21 27

Read also

← All articles