Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Weak passwords were the dominant identity-attack route in Microsoft’s 2024 identity telemetry, but stolen credentials are only one part of the problem. MFA can be targeted, tokens can be stolen after sign-in, and poorly governed applications or identity infrastructure can create openings. Microsoft’s figures describe its own telemetry; Verizon’s 2024 Data Breach Investigations Report (DBIR) summarizes incidents and breaches from 2023. They offer complementary perspectives, not a single measure of identity failures across all organizations.

What the 2024 findings say about identity exposure

Microsoft Threat Intelligence classified more than 99% of the identity attacks shown in its 2024 Digital Defense Report as password attacks. It identifies breach replay, password spraying and phishing as common routes, enabled in part by predictable or reused passwords and susceptibility to phishing. This is a finding from Microsoft’s identity telemetry, not a worldwide estimate of every organization’s incidents. Microsoft Digital Defense Report 2024.

Verizon’s 2024 DBIR supplies a different view: its analysis covered 30,458 security incidents and 10,626 confirmed breaches from 2023. Verizon reported that a non-malicious human element was involved in 68% of breaches, and that stolen credentials appeared in almost one-third (31%) of breaches over the preceding ten years. These figures provide context for mistakes, social engineering and credential abuse; they are not a 2024 rate of identity lapses. Verizon’s 2024 DBIR release.

How identity attacks progress beyond a password

Microsoft’s chart groups the illustrated identity-attack routes into four stages or types. The other categories account for less than 1% combined in that figure, but their smaller share does not make them harmless: they can bypass, abuse or outlast a successful sign-in.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Attack route What can happen Relevant control layer
Password attacks Breach replay, password spraying or phishing can expose a user account, particularly when passwords are predictable or reused. MFA, stronger sign-in methods and monitoring.
MFA attacks SIM swapping, MFA fatigue or adversary-in-the-middle (AiTM) phishing can undermine or capture an authentication flow. Phishing-resistant MFA, especially for administrators.
Post-authentication attacks Token theft or consent phishing can let an attacker abuse access after the user has authenticated. Monitor identities, applications, permissions and access activity.
Identity-infrastructure compromise Attackers may target federation signing keys, privileged cloud identities or workload identity credentials. Govern identity infrastructure, privileged access and non-human identities; monitor configuration changes.

These categories and examples come from Microsoft’s 2024 report; they are not a ranking of risk for every organization. Identity security must account for the whole access path, not just the password prompt. Microsoft Digital Defense Report 2024.

Why non-human identities and neglected assets matter

An organization’s identity footprint extends beyond employee accounts. Microsoft highlights exposure from abandoned or unmonitored tenants; applications and workload identities without clear ownership or governance; developer secrets exposed in public code repositories; and storage repositories with inadequate access controls. Any of these can leave access or credentials active without an accountable owner.

  • Tenants and applications: identify who owns each environment and application, review whether it is still needed, and retire abandoned assets.
  • Workload identities and secrets: assign an owner, govern credentials, and look for exposed secrets in code repositories.
  • Permissions and storage: minimize application permissions and ensure repositories are not more accessible than their purpose requires.

These are governance and access-control concerns, not simply password problems. Microsoft’s guidance emphasizes inventorying and governing these assets. Microsoft Digital Defense Report 2024.

What organizations should do about identity weaknesses

1. Require MFA and strengthen administrator sign-in

Microsoft recommends MFA for all users and phishing-resistant MFA for administrators. It reports that requiring users to enroll in MFA reduces identity-compromise risk by 99.2%. That is Microsoft’s estimate, not a guarantee for every deployment or a claim that MFA blocks every identity attack. Stronger methods matter because MFA fatigue and AiTM phishing can target weaker authentication flows. Microsoft Digital Defense Report 2024.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Move toward phishing-resistant, passwordless sign-in

Where systems and policy support it, plan a migration toward phishing-resistant passwordless methods such as passkeys. This complements MFA by reducing reliance on passwords and sign-in flows that can be phished. The appropriate method depends on the organization’s identity platform and operational requirements. Microsoft Digital Defense Report 2024.

3. Monitor identity systems and what they trust

Monitor identity infrastructure, access paths and configuration changes, as well as the devices and networks on which those systems depend. Include privileged cloud users, federation components, applications and workload identities in that view; a valid sign-in does not rule out token theft or later misuse. Microsoft Digital Defense Report 2024.

4. Make ownership and cleanup routine

Maintain an inventory of tenants, applications, workload identities and credentials. Establish owners, review permissions, remove access that is no longer needed, and retire abandoned assets. Check repositories for exposed developer secrets and review storage access controls. These steps address the identity and access gaps Microsoft identifies, including ones that can persist after employees or projects change. Microsoft Digital Defense Report 2024.

5. Make phishing reporting easier and more useful

Training is only one part of the response; employees also need a clear, supportive way to report suspicious messages. Verizon reported that 20% of users identified and reported phishing in simulation engagements; among users who clicked the simulated email, 11% also reported it. Those are simulation findings, not a prediction of how every workforce will behave. Use reporting to improve response and reinforce good practice rather than discourage people from raising a concern. Verizon’s 2024 DBIR release.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Keep vulnerability remediation in the broader security plan

Identity controls cannot compensate for every weakness in the systems around them. Verizon reported an average of 55 days for organizations to remediate 50% of critical vulnerabilities after patches were available. Separately, the median time to detect mass exploitation of CISA’s Known Exploited Vulnerabilities catalog on the internet was five days. These are distinct vulnerability-management measures, not identity-specific statistics, but they illustrate why patching and detection belong alongside identity hygiene. Verizon’s 2024 DBIR release.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to interpret the scale without overreading it

The 2024 findings are useful because they show different parts of organizational exposure: Microsoft’s identity telemetry points to password attacks and other routes through identity systems, while Verizon’s breach analysis describes human involvement and stolen credentials in a broader incident dataset. The measures have different scopes, time periods and denominators. They should not be combined into a single rate or treated as proof that every organization faced the same pattern.

Microsoft’s CISO executive summary captured the prioritization challenge in a statement from CEO Satya Nadella: “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security. In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems.” Microsoft Digital Defense Report 2024.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.