If you imagine the attack that's most likely to compromise one of your customers this year, you probably picture something sophisticated — a zero-day, a clever bit of malware, a hooded figure and a lot of green text. The reality is far more boring, and that's exactly why it's so dangerous.
The attacks breaking into Microsoft 365 tenants aren't exotic. They're password spraying and credential stuffing — guessing and reusing passwords at scale. They work not because they're clever, but because they're relentless, and because the defences that stop them aren't applied consistently across every tenant. Let's look at the numbers, then talk about why "boring" keeps winning and what actually fixes it.
The numbers are almost embarrassing
Here's the state of play, drawn from Microsoft's threat intelligence as summarised for MSPs by Syncro:
- Identity-based attacks surged 32% in the first half of 2025. Identity is the front line, and the pressure is increasing fast.
- More than 97% of all identity attacks are simple password attacks — password spraying, credential stuffing, the basics. Not sophisticated, just high-volume.
- Multi-factor authentication blocks over 99% of identity-based attacks.
Sit with that combination for a second. The overwhelming majority of identity attacks are crude, and a control that's been available for years stops virtually all of them. This isn't a problem waiting on some future technology. The fix exists, it's cheap, and it works. The attacks succeed anyway — which tells you the problem isn't capability. It's consistency.
Why "boring" keeps winning
If MFA stops 99%+ of these attacks, why are they still the dominant way into M365? Because at MSP scale, the gap is never about a single tenant. It's about every tenant, configured consistently, and kept that way over time.
Think about how the failure actually happens across a real book of business:
- One customer onboarded before you standardised on MFA everywhere, and a few legacy accounts never got covered.
- Another has a conditional access policy that looks right but has an exclusion someone added for a temporary project and never removed.
- A break-glass account sits without proper protection "just in case."
- A new tenant came on board last month and its baseline doesn't quite match your standard yet.
Each of these is a small, individually forgivable gap. But attackers don't need you to be uniformly weak — they just need one unlocked door among the hundreds you manage. Password spraying is automated and patient; it will find the one account, in the one tenant, where the control slipped. Your security posture across your whole estate is only as strong as your least-consistently-configured tenant.
That's the real challenge identity attacks expose. It's not that MSPs don't know MFA works. It's that proving every account across every tenant is actually covered — and staying on top of drift as policies and people change — is genuinely hard when each tenant lives behind its own admin centre.
The cost of finding out the slow way
When these attacks succeed, the damage compounds with time. Stolen credentials often get sold on to access brokers — the Lumma Stealer infostealer was the most prevalent observed between October 2024 and October 2025, harvesting credentials from browsers and apps to feed exactly this market. An attacker with valid credentials doesn't look like an attacker; they look like a user. That's why the dwell time on identity compromises can be so long, and why catching anomalies quickly matters so much.
The encouraging flip side: speed pays. IBM's 2025 data, cited in incident-response analysis, shows organisations using AI and automation cut their breach lifecycle by around 80 days and saved roughly $1.9 million per incident. Detecting and responding faster isn't just tidier — it's materially cheaper.
How DendronAI closes the consistency gap
Stopping boring identity attacks comes down to two things: making sure the right controls are actually in place everywhere, and catching the anomalies that slip through quickly. DendronAI is built to do both across every tenant at once, rather than one admin centre at a time.
Cross-tenant visibility of identity risk. The ITDR app surfaces the exact signals these attacks generate — risky sign-ins, impossible travel, privilege escalation, suspicious mailbox rules — across all your tenants in a single console. A risky sign-in attempt from an unexpected country in one customer's tenant doesn't sit buried in a portal nobody checked this week; it shows up where your team is already looking.
An MTTR you can actually act on and report. Because alerts are consolidated and triage happens in one place built for MSPs — not a SIEM you fight with — you can respond in minutes rather than discovering a compromise months later. DendronAI reports a 14-minute median MTTR, and just as importantly, an MTTR you can put in front of a customer in a QBR.
Finding the drift before attackers do. This is where the Graph explorer earns its place. You can run a single Graph query across one tenant or every tenant to answer exactly the questions that catch gaps: which accounts don't have MFA enforced, which conditional access policies have risky exclusions, where the baseline has drifted from your standard. Then save the report, schedule it, and share it. Instead of hoping every tenant is consistent, you can prove it on a schedule — and fix what isn't with cross-tenant operations that let you preview and roll back a change.
That combination directly attacks the reason boring attacks keep winning: it turns "are all my tenants consistently protected?" from an unanswerable worry into a scheduled report.
The fair caveats
A balanced word. MFA is overwhelmingly effective, but it isn't infallible — MFA-fatigue and adversary-in-the-middle phishing can defeat weaker MFA methods, so the goal should be phishing-resistant MFA, not just any second factor. Visibility tooling reduces dwell time, but it doesn't replace the foundational work of getting strong authentication enforced everywhere in the first place; detection is the safety net, not the primary control. And no platform removes the need for sensible policy design — it makes that design consistent and visible across your estate, which is a different (and very valuable) thing.
The takeaway
The most likely way one of your customers gets compromised this year is depressingly unsophisticated: someone, somewhere, guesses or reuses a password against an account where the control slipped. The defence has existed for years and stops over 99% of these attacks. The only real question is whether it's applied — and stays applied — across every account in every tenant you manage.
If you'd like to see how DendronAI gives you cross-tenant identity visibility and lets you prove your baseline holds everywhere, take a look. We'll show you the boring attack that still owns customers — and how to make sure it doesn't own yours.