Source: Daniel Rubino/Windows Central
What you need to know
- 99.9 percent of compromised Microsoft accounts don't have multi-factor authentication enabled.
- 1.2 million Microsoft accounts were compromised in January 2020.
- Microsoft emphasized the risks of not using multi-factor authentication at the RSA security conference last week.
Around 1.2 million Microsoft accounts were compromised in just January 2020, and almost all of them could have been secured by enabling a single setting. According to Microsoft engineers, 99.9 percent of the compromised accounts they track do not use multi-factor authentication. Microsoft discussed account security and the risks of not using multi-factor authentication at the RSA security conference last week (via ZDNet).
At the RSA conference, Microsoft pointed out that it tracks more than 30 billion login events every day. On average, 0.5 percent of accounts get hacked, but with over one billion active users, that means that around 1.2 million accounts were compromised in January alone.
Microsoft emphasized the enterprise risk of not having multi-factor authentication enabled. Enterprise users often have sensitive data on their systems. Despite often holding sensitive data, only 11 percent of enterprise users have multi-factor authentication enabled in January 2020, according to Microsoft.
According to Microsoft, the most common form of attack to hack Microsoft accounts is password spraying. This technique takes easy-to-guess passwords and goes through a list of usernames until an attacker can get into the account.
The second most common method of attack is password replay. With this technique, an attacker takes leaked credentials from another company and tries them with a Microsoft account. It relies on people using the same password across multiple accounts. Lee Walker, Identity and Security Architect at Microsoft, says that 60 percent of users reuse passwords. He also adds, "Don't be confused. People reuse their enterprise accounts in non-enterprise environments."
According to Walker, the vast majority of attacks utilizing password spraying and password replay attack older legacy authentication protocols. Specifically, 99 percent of all password spray attacks and 97 percent of password replay attacks go through legacy authentication protocols. This is because these legacy protocols don't support multi-factor authentication, according to Microsoft. Microsoft states that companies that disable legacy authentication protocols see a 67 percent reduction in compromised accounts.
The easiest solution to reduce security risks, according to Microsoft, is to enable multi-factor authentication. Microsoft states that your account is more than 99.9 percent less likely to be compromised if you enable multi-factor authentication.
There's really no excuse not to use multi-factor authentication at this point.
We may earn a commission for purchases using our links. Learn more.

Here's what Minecraft can learn and take from Minecraft Earth
Minecraft Earth is on its way out for a number of reasons, but that doesn't mean there aren't some great ideas vanilla Minecraft can learn from and take for itself.

Should you get an XPS 13 or XPS 15?
Have your heart set on a new Dell XPS laptop but not sure which one to go for? Let us help as we break down some of the key points to consider.

These are all our picks for the very best Windows laptops available
The HP Spectre x360 13 is our pick for the best overall Windows laptop you can buy, but there are a ton of other great options if you need something different. If you're now working from home and need a quality device, you'll find it here.

These are the best PC sticks for when you're on the move
Instant computer, just add a screen! That’s the general idea of the ultra-portable PC Compute Sticks, but it can be hard to know which one you want. Relax, we’ve got you covered.