Microsoft sheds some light on Russian email heist – and how to learn from Redmond’s mistakes

Step one, actually turn on MFA

Microsoft, a week after disclosing that Kremlin-backed spies broke into its network and stole internal emails and files from its executives and staff, has now confirmed the compromised corporate account used in the genesis of the heist didn’t even have multi-factor authentication (MFA) enabled. …

This article has been indexed from The Register – Security

Read the original article: