Decision RecordActivePublished without chair review

Require phishing-resistant authentication for privileged Microsoft 365 access

Privileged Microsoft 365 authentication

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
Section support
0/8 backed · 2 gaps · panel
Severity
High
Assessed severity
Panel
AI roles · 1 disagreement
Freshness · v1
Last updated 1 day ago
Last revised 2026-09-09
Active2 evidence references · Published 09 Sep 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

Require phishing-resistant FIDO2 or WebAuthn authentication for privileged Microsoft 365 identities and prevent fallback to passwords, SMS, TOTP, or push approval during normal sign-in.

Public guidance

Current public guidance · the full record

Current public value version · v1
01

What to do now

At a glance

The edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.

02

Why now

Under review

Reporting reviewed on September 9, 2026 attributed 1,032 plaintext passwords and 4,148 session cookies to the BigBear 2.0 activity.

It also reported that 258 organizations had at least one completed MFA-bypass record, compared with 461 in the broader targeting dataset.

Although those figures lack independent tenant-level confirmation, they identify an immediate policy question: whether privileged Microsoft 365 sign-ins can still fall back from FIDO2 or WebAuthn to passwords, SMS, TOTP, or push approval.

03

Who is affected

Under review

Privileged Microsoft 365 identities in tenants that permit password, SMS, TOTP, or push fallback during normal sign-in face the reported risk that suppression of FIDO2 or WebAuthn redirects authentication to a reusable factor and enables session capture.

Identity administrators for those tenants must remove the fallback paths and test fail-closed behavior.

Tenants already requiring FIDO2 or WebAuthn without weaker fallback should verify that an unavailable phishing-resistant method produces a blocked privileged sign-in rather than another authentication prompt.

04

What supports this

Partially supported
  1. Supporting analysis: The recorded identity-architecture analysis says WebAuthn is reportedly suppressed rather than cryptographically bypassed, and that weaker-factor fallback permits proxied authentication and reusable session capture. Its stance supports requiring phishing-resistant authentication without fallback.
  2. Reported incident context: CloudSEK reports 1,032 plaintext passwords and 4,148 session cookies, while BleepingComputer reports completed MFA-bypass records involving 258 organizations out of 461 in the broader targeting dataset. This supports urgency but does not independently confirm every Microsoft 365 tenant compromise.
  3. Retrieval records: Two searches targeted BigBear 2.0, FIDO2 suppression, Microsoft 365 session theft, and the reported counts. Their stance is an evidence gap because they expose query terms and truncated listings rather than the underlying technical sources.
05

How the Roundtable reached this

Under review

The decision scout identified weaker authentication fallback as the actionable control gap for privileged Microsoft 365 access.

The supporting analysis distinguished reported WebAuthn suppression from a cryptographic bypass and concluded that mandatory FIDO2 or WebAuthn would make the downgrade attempt fail closed.

The evidence auditor supported that control but found that the BigBear 2.0 mechanism lacked a primary technical source and tenant validation. The boundary reviewer resolved this by retaining the defensive action while treating the named mechanism as reported rather than independently proven.

The linker found no existing decision for comparison, and the arbiter selected a new decision based on the supported authentication control.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 11 candidate signals.
  • Linker (AI panel role)Linker evaluated 11 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 29 evidence signals; 19 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 16 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 11 decision envelopes.

Key disagreement

Scout (AI panel role)

Confidence is stronger in the attack mechanics than in the exact number of affected organizations, and the packet lacks independent tenant telemetry confirming every reported compromise.

Arbiter outcome

Arbiter outcome: new decision record. The core authentication control is supported, and uncertainty about the named attack mechanism can be handled through attribution-safe wording.

Candidates considered

Considered 11 candidates · opened 1 · 10 not opened (10 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06

What is uncertain

Missing

The exact BigBear 2.0 scope and attributed mechanism remain uncertain.

Reporting says 258 organizations had at least one completed MFA-bypass record and 461 appeared in a broader targeting dataset, but the packet contains no independent tenant telemetry confirming every reported compromise.

The available retrieval material is insufficient to verify independently that BigBear 2.0 suppresses WebAuthn and depends on weaker fallback. The defensive value of blocking fallback is better supported than those attribution and scope claims.

07

What evidence is missing

Missing

The packet does not contain the primary BigBear 2.0 technical report, full source material establishing its WebAuthn-suppression and session-capture mechanism, Microsoft authentication-policy guidance, or independent Microsoft 365 tenant telemetry.

It also supplies no Microsoft 365 version or tenant-configuration matrix showing where password, SMS, TOTP, or push fallback remains available. These gaps limit attribution and scope validation, not the general case for removing weaker fallback from privileged sign-ins.

08

What would change this

Under review

The control rationale would require reassessment if primary technical evidence showed that BigBear 2.0 can bypass FIDO2 or WebAuthn cryptographically even when password, SMS, TOTP, and push fallback are blocked.

Authoritative Microsoft guidance showing that the listed fallback methods cannot be disabled for privileged normal sign-in would change the implementation path.

Independent tenant telemetry disproving the reported compromises would reduce the attributed scope and urgency, while leaving the general value of phishing-resistant authentication intact.

09

What to watch next

Under review

Repeat the controlled fail-closed test after each privileged Microsoft 365 authentication-policy change.

Treat any offer or use of password, SMS, TOTP, or push approval after FIDO2 or WebAuthn becomes unavailable as a trigger to correct enforcement. Monitor privileged authentication and session telemetry for weaker-factor sign-ins and reusable-session activity.

Reassess the attributed BigBear 2.0 mechanism and reported scope when a primary technical report, Microsoft guidance, or independent tenant-level confirmation becomes available.

Sources & context

Evidence basis

2 references
Context
The new reporting strengthens—but does not overturn—my position. **Fact:** CloudSEK reports 1,032 plaintext passwords an…

The new reporting strengthens—but does not overturn—my position. **Fact:** CloudSEK reports 1,032 plaintext passwords and 4,148 session cookies; BleepingComputer says 258 organizations had at least one completed MFA-bypass record, versus 46…

Observed 9 Sept 2026
Revision trail

Public value history

1 event on record
1 value version · 1 update · 0 predictions
  1. 09 Sep 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.