Multi-Factor Authentication

T1556.006

Sub-technique of T1556 Modify Authentication Process.View on attack.mitre.org

About this technique

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Once adversaries have gained access to a network by either compromising an account lacking MFA or by employing an MFA bypass method such as Multi-Factor Authentication Request Generation, adversaries may leverage their access to modify or completely disable MFA defenses. This can be accomplished by abusing legitimate features, such as excluding users from Azure AD Conditional Access Policies, registering a new yet vulnerable/adversary-controlled MFA method, or by manually patching MFA programs and configuration files to bypass expected functionality.

For example, modifying the Windows hosts file (`C:\windows\system32\drivers\etc\hosts`) to redirect MFA calls to localhost instead of an MFA server may cause the MFA process to fail. If a "fail open" policy is in place, any otherwise successful authentication attempt may be granted access without enforcing MFA.

Depending on the scope, goals, and privileges of the adversary, MFA defenses may be disabled for individual accounts or for all accounts tied to a larger group, such as all domain accounts in a victim's network environment.

Detection rules14

Rules on DetectionCode tagged with T1556.006.

Sigma3

Splunk11

RuleTypeRiskData source
ASL AWS Multi-Factor Authentication DisabledTTPNULLASL AWS CloudTrail
ASL AWS New MFA Method Registered For UserTTPNULLASL AWS CloudTrail
AWS Multi-Factor Authentication DisabledTTPNULLAWS CloudTrail DeleteVirtualMFADevice, AWS CloudTrail DeactivateMFADevice
AWS New MFA Method Registered For UserTTPNULLAWS CloudTrail CreateVirtualMFADevice
Azure AD Multi-Factor Authentication DisabledTTPNULLAzure Active Directory Disable Strong Authentication
Azure AD New MFA Method Registered For UserTTPNULLAzure Active Directory User registered security info
GCP Multi-Factor Authentication DisabledTTPNULLGoogle Workspace
Okta Multi-Factor Authentication DisabledTTPNULLOkta
PingID Mismatch Auth Source and Verification ResponseTTPNULLPingID
PingID New MFA Method After Credential ResetTTPNULLPingID
PingID New MFA Method Registered For UserTTPNULLPingID

Groups1

Software2

Campaigns1

Procedure examples4

Groups1

Used byProcedure example
GroupScattered Spider

After compromising user accounts, Scattered Spider registers their own MFA tokens.

Software2

Used byProcedure example
ToolAADInternals

The AADInternals `Set-AADIntUserMFA` command can be used to disable MFA for a specified user.

MalwareSLOWPULSE

SLOWPULSE can insert malicious logic to bypass RADIUS and ACE two factor authentication (2FA) flows if a designated attacker-supplied password is provided.

Campaigns1

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries modified two-factor settings within the FortiGate solution to `unset`.

References3

  1. Azure AD Conditional Access Exclusions Open source
    Microsoft. (2022, August 26). Use Azure AD access reviews to manage users excluded from Conditional Access policies. Retrieved August 30, 2022.
  2. Mandiant APT42 Open source
    Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromise. Retrieved September 16, 2022.
  3. Russians Exploit Default MFA Protocol - CISA March 2022 Open source
    Cyber Security Infrastructure Agency. (2022, March 15). Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and “PrintNightmare” Vulnerability. Retrieved May 31, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.