---
title: "Why MFA is no longer enough (SIEM, EDR) | Avepto"
canonical_url: "https://avepto.ch/en/articles/mfa-not-enough-session-theft-siem-edr"
last_updated: "2026-08-30T17:21:46.000Z"
locale: en
meta:
  author: "Yoann Talagrand"
  description: "Session-token theft, proxy phishing, invisible mailbox rules: why MFA alone is no longer enough, and how SIEM and EDR close the door."
  "og:description": "Session-token theft, proxy phishing, invisible mailbox rules: why MFA alone is no longer enough, and how SIEM and EDR close the door."
  "og:title": "Why MFA is no longer enough (SIEM, EDR)"
  "twitter:description": "Session-token theft, proxy phishing, invisible mailbox rules: why MFA alone is no longer enough, and how SIEM and EDR close the door."
  "twitter:title": "Why MFA is no longer enough (SIEM, EDR)"
---

![A travertine pivot door standing ajar onto a sunlit courtyard, with a brass pull.](https://assets.avepto.ch/cdn-cgi/image/w=1280,h=853,f=auto,q=75,fit=cover/d67f74a5-15d7-467e-9824-31ddd54134f1.png)

# MFA enabled, account compromised: why two-factor authentication is no longer enough

Session-token theft and invisible mailbox rules: what MFA cannot see, and what can

<dl>

<dt>Written by</dt>
<dd>Yoann Talagrand</dd>

<dt>Publication date</dt>
<dd>11 August 2026</dd>

<dt>Last updated</dt>
<dd>13 September 2026</dd>

<dt>Reading time</dt>
<dd>About seven minutes</dd></dl>

Podcast

The article takes the floor. A conversation generated by artificial intelligence.

Two to three days: that is the median time an attacker moves around a compromised environment before being detected, according to the Sophos Active Adversary reports for 2025 and 2026. And quiet intrusions, the ones without ransomware, often last far longer. Not only in careless companies: also in Swiss SMEs with multi-factor authentication (MFA) enabled for everyone and a password policy in place. On paper, everything is in order. In practice, it isn’t enough, and that is exactly the misunderstanding to correct.

## MFA is the badge at the entrance, and nothing more

The code from the Authenticator app you type every morning to reach your email: that measure is indispensable. But it protects one single moment, the moment you enter your password.

Picture the front door of an office building. MFA is the badge. You beep, you walk in. But once inside the building, nobody asks you anything. You wander the corridors, you open doors. Attackers have understood this perfectly: they no longer force the door. They wait for someone to open it for them.

### Reverse-proxy phishing: the real page, the fake context

The most common technique today is not a crude copy of a login page. It is far more sophisticated. Tools like EvilProxy work as a real-time mirror: the employee receives a carefully crafted email, a SharePoint notification, a security alert. They click, and land on the genuine Microsoft login page.

They type their username. They confirm on their Authenticator. Everything looks normal. But between them and Microsoft, a silent proxy intercepts everything, including the session token.

### Token theft: walking in without ever forcing MFA

The session token is the small file that lets your browser stay signed in all day without retyping your password at every click. Once you authenticate, Microsoft hands you that token, and it stays valid for hours, sometimes days.

When an attacker steals that token, they no longer need your password. They no longer need MFA. They sign in to your account as if they were you, and Microsoft is none the wiser.

## Days of silence: what happens once they’re in

Once inside, the attacker doesn’t rush. They observe. And the first thing they do is systematic.

### Mailbox rules: the invisible spy

They create an inbox rule. A discreet one. Something like: any message containing the word “invoice” or “IBAN”, move to a folder nobody checks. Who reviews their inbox rules regularly? Almost no one. And that’s normal: it’s precisely what attackers count on.

Microsoft does generate some alerts by default, but they land in a console nobody opens. Attackers know it: they favour discreet rules that move messages to ignored folders, rather than automatic external forwarding, which Exchange often blocks out of the box.

For weeks, they read every exchange that mentions a payment. They learn how the company works, who signs the transfers, who approves what. Then comes the moment to strike.

### IBAN fraud: the genuine document, the falsified number

The classic scenario: a fake email from the boss demanding an urgent transfer. But there is something more vicious still. The attacker changes the IBAN on a real, existing invoice. The document is authentic in its form, its content, its apparent sender. Only the account number has changed. The person making the transfer has no reason to be suspicious.

These cases are not theoretical. They are handled regularly, in French-speaking Switzerland, in SMEs that did what they had been told to do.

### Microsoft 365 records a great deal, and alerts far too little

Here is the most dangerous illusion: believing that because Microsoft 365 logs everything, someone is watching. The platform generates thousands of events a day. It is a gold mine. But it is like having security cameras all over a building with nobody in front of the screens.

Take this typical example: your accountant signs in at 9:15 from Geneva. Three minutes later, their account is active from a server in Asia. Physically impossible. It is called an impossible travel. By default, the event ends up in a log nobody opens. The same goes for modified SharePoint permissions or third-party apps acquiring access.

## The SIEM: connecting the dots to tell a story

Separate signals mean nothing. What matters is the story they tell together. A strange login from Asia, a newly created mailbox rule, access to a confidential folder: an attack in progress. But to draw that conclusion, you need a tool that cross-references the information automatically.

That is the role of the SIEM (Security Information and Event Management). Picture a doctor who doesn’t just look at your temperature. They take your blood pressure, your blood tests, your history, and cross-check it all to reach a diagnosis. The SIEM does the same: it receives data from Microsoft 365, from workstations, from firewalls, and connects the dots into a coherent story.

It is what triggers the alert. Not in several days: within minutes. And coupled with a managed monitoring service like ours, that alert lands with analysts available around the clock, who can isolate the account within minutes. In the impossible-travel scenario, the attacker doesn’t even get time to create their mailbox rule. Days versus fifteen minutes: that is the whole difference between managing a crisis and managing an incident.

## The EDR: the bouncer who watches behaviour

A classic antivirus works like a bouncer with a guest list: if a file is known to be dangerous, it is blocked. But if the threat isn’t on the list, it walks in.

The EDR (Endpoint Detection and Response) watches behaviour, not signatures. A bouncer who sees someone enter the room and start going through other people’s pockets steps in, even if they’re on no list. Concretely: a process encrypting files in bulk, a script trying to exfiltrate data, an application modifying system registry keys. The EDR detects these behaviours and automatically isolates the machine from the network within seconds, without waiting for a human to decide.

## A 60-minute audit to know where you really stand

You often hear that this level of protection, SIEM, EDR, round-the-clock analysts, is for multinationals. That is no longer true. These tools are now sized for organisations of twenty, thirty, fifty people. And above all, you don’t have to operate them yourself: a provider like Avepto does it for you, without you having to hire anyone.

But before all that, the first step is a 60-minute audit. Without mobilising your team, without jargon. We check the points that do the most damage when misconfigured:

- Is MFA enabled for all accounts, including the forgotten ones? (There are usually two or three left.)
- Is SMS still used as a verification method? It is the easiest to intercept: the Authenticator app or a hardware key is the minimum.
- Are there active mailbox rules nobody consciously created?
- Are there active sessions from suspicious locations?
- Have third-party applications acquired access to the environment for no clear reason?
- Are OneDrive or SharePoint folders accessible to anyone holding the link?

That last point always surprises. A significant number of SMEs have confidential SharePoint folders open to anyone with the URL. Nobody did it on purpose: a supplier was given temporary access, and the link was never restricted. Months, sometimes years later, that folder is still public.

At the end of the audit, you have a clear view of your blind spots. No 80-page report. Facts, ranked by priority.

## What the law says, and why it concerns your 20-person SME too

Switzerland’s [new Federal Act on Data Protection (nFADP)](https://www.fedlex.admin.ch/eli/cc/2022/491/en) requires appropriate technical and organisational measures, and the recommendations of the [OFCS (Federal Office for Cybersecurity)](https://www.bacs.admin.ch/en) point clearly the same way: logging and access control are now part of the basic hygiene expected of any organisation handling personal or financial data.

Even a 20-person SME that thinks its data isn’t “sensitive” is concerned. Client data, IBANs, contracts: always sensitive in the eyes of the law, and even more so in the eyes of an attacker who knows exactly how to monetise them.

Our [managed cybersecurity offering](https://avepto.ch/en/cybersecurity) covers precisely these blind spots. [Request your 60-minute audit](https://avepto.ch/en/contact): you’ll know where you stand before someone else finds out for you.