Free tools Windows power users keep installed
One-click scans. No signup required.
Attackers can get into cloud accounts despite MFA when they steal a valid session or token, persuade a user to approve a sign-in or reset, or use a legacy authentication path where modern MFA controls do not apply. That is different from breaking MFA cryptographically: the weak point may be the account-recovery process, an unsupported protocol, or an already authenticated session.
How credential dumps lead to cloud account breaches
A credential dump is a collection of login details exposed through a data breach or other theft. Attackers may test those credentials against cloud services, but an exposed password is not automatically a working cloud login: it may be stale, already changed, belong to another service, or still require MFA. Phishing can also steal credentials directly by leading a user to enter them into a deceptive sign-in flow.
Google Cloud reported that weak or absent credentials were involved in 47.1% of observed initial-access incidents in its H1 2025 reporting. The same report attributed 2.9% of observed initial access to leaked credentials and 29.4% to misconfiguration. These are figures from incidents observed in Google Cloud’s environment, not estimates for all cloud providers or organizations worldwide; the categories should not be treated as a global prevalence rate. Google Cloud, Cloud Threat Horizons Report H1 2026.
Can attackers bypass MFA?
Yes, but “bypass” covers different attack paths. In many cases, attackers do not defeat the cryptography behind an MFA factor; they exploit how a person, recovery flow, protocol, session, or application handles authentication.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Attack path | What happens | Why MFA may not stop it |
|---|---|---|
| Stolen password | An attacker tries a password obtained through phishing or exposure. | A correctly enforced second factor can block a password-only login, but the password may still enable further attacks or be used where MFA is not enforced. |
| Social engineering or recovery abuse | A user is persuaded to approve a prompt, complete a reset, or register a new authentication method. | The user or recovery process may authorize the attacker’s access. |
| Adversary-in-the-middle or device-code phishing | A user is induced to authenticate through a flow controlled by the attacker. | The attacker may capture a valid token or authenticated session rather than merely learning a password. |
| Legacy authentication | A client or protocol signs in through an older authentication path. | Some legacy protocols do not support modern MFA enforcement. |
| Stolen session or token | An attacker reuses access that has already been authenticated. | A password change alone may not invalidate every existing session or token. |
Prompt, reset and authentication-method abuse
Microsoft described a Storm-2949 campaign in which users were persuaded to complete apparently legitimate MFA prompts associated with self-service password reset. The actor then reset passwords and registered its own authentication method. This is one investigated campaign, not a sequence that should be assumed in every account compromise. Microsoft’s Storm-2949 incident analysis.
Captured tokens and sessions
In September 2026, Microsoft reported a passkey-themed pretext used to draw users into adversary-in-the-middle or device-code authentication flows. Its account describes how stolen tokens, unrevoked sessions, or valid credentials could help make attacker-controlled MFA enrollment more durable. A token or authenticated session is not the same thing as a password: it can represent access already granted by an earlier sign-in. Microsoft’s analysis of passkey-themed social engineering.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What phishing-resistant MFA changes
Phishing-resistant authentication helps prevent a user from completing authentication on an impostor site. CISA identifies FIDO/WebAuthn as the only widely available phishing-resistant authentication method. Where it is not yet available, CISA identifies number matching as an interim choice; neither option removes the need to manage legacy protocols or stolen sessions. CISA, More than a Password.
What is legacy authentication, and why do POP, IMAP and SMTP matter?
Legacy authentication refers here to older client or protocol sign-in methods that may not support the stronger authentication controls used by modern cloud sign-ins. POP and IMAP are email-retrieval protocols associated with older client compatibility. SMTP AUTH is used by some applications and devices to send email. Whether any of these paths are enabled or exposed depends on the service and tenant configuration.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
CISA advises organizations to understand which authentication methods their legacy protocols support and to disable methods that cannot support strong authentication in line with risk tolerance. Its Microsoft Entra baseline recommends blocking legacy authentication because those protocols do not support MFA. These are configuration recommendations, including guidance aimed at federal environments; they do not mean every legacy client is malicious. CISA, TIC 3.0 Cloud Use Case and CISA, SCuBA Microsoft Entra baseline.
Does MFA protect email if POP or IMAP is enabled?
It depends on the authentication path the client actually uses and the controls enforced for that path. Enabling a protocol does not by itself establish that MFA is being applied to every sign-in through it. CISA’s guidance is to identify legacy-protocol use, determine which authentication methods it allows, and disable paths that cannot support strong authentication when the risk justifies doing so.
Rank #4
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
SMTP AUTH in Exchange Online
CISA’s Exchange Online baseline says MFA cannot be enforced while using SMTP AUTH. It recommends disabling SMTP AUTH globally and allowing a per-mailbox exception only where an application has a genuine need. Inventory applications and dependencies before changing production settings so a legitimate mail-sending workflow is not unexpectedly interrupted. CISA, SCuBA Exchange Online baseline.
How to identify and block legacy sign-ins
- Review sign-in logs. Identify which users, clients, protocols, and applications are using legacy authentication. CISA’s Exchange Online migration guide specifically directs administrators to identify legacy-authentication clients in sign-in logs. CISA, Switch to Modern Authentication in Exchange Online.
- Confirm business dependencies. Find out whether a device, application, or service account still relies on the protocol. Plan a modern-authentication replacement where available, and document any exception that cannot yet be removed.
- Block unsupported paths. Apply the provider’s current controls to block legacy sign-ins that cannot enforce strong authentication. For Exchange Online, assess SMTP AUTH use and follow the CISA baseline’s global-disable recommendation, using only a narrowly scoped mailbox exception for a documented application need.
- Verify the change. Check logs and application behavior after enforcement. Investigate unexpected legacy sign-ins, and revise exceptions rather than leaving broad access in place to solve a single application problem.
Exact settings and client availability can vary by provider and tenant. Check current provider documentation and your own configuration before making a production change.
Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
What happens after the first cloud sign-in?
A successful login may be only the start. An intruder can look for identities and permissions in the directory, try to establish persistence, access email or files, or exploit connected applications and their granted permissions. In Microsoft’s Storm-2949 account, the actor used Microsoft Graph for enumeration and made an unsuccessful attempt at service-principal persistence. Google Cloud advises governing OAuth applications and scopes and monitoring cloud access. These reports describe investigated activity and defensive guidance, not a claim that every compromise follows the same pattern. Microsoft’s Storm-2949 incident analysis and Microsoft Digital Defense Report 2025.
Quick Recap
What to do if an account may be compromised
- Contain the identity. Reset exposed or suspected-compromised credentials and investigate unexpected sign-ins, MFA changes, password resets, and new authentication-method registrations.
- Revoke sessions and tokens. Use the provider’s incident-response controls to invalidate active sessions and tokens where possible. A password reset alone may not remove every previously issued token or session; understand the provider’s revocation behavior and account for it in the response procedure.
- Review connected access. Check OAuth applications, third-party integrations, granted scopes, and unusual mailbox or file access. Remove permissions that are not needed and investigate suspicious application activity. Microsoft’s 2026 account of token and session abuse and Microsoft Digital Defense Report 2025.
- Check for persistence and data access. Examine directory changes, newly added applications or service principals, email access, and cloud-file activity for actions the affected user did not perform.
- Close the entry path. Determine whether access came from a reused password, a social-engineering flow, legacy authentication, or a captured session or token. Address that path before returning the account to normal use.
Defenses that reduce the risk of a repeat breach
- Require phishing-resistant MFA, especially for administrators and accounts with access to sensitive data. CISA recommends FIDO/WebAuthn; it describes number matching as an interim option where phishing-resistant MFA is not yet available. CISA, More than a Password.
- Reduce legacy-authentication exposure. Find legacy clients in sign-in logs, migrate supported workflows, and block authentication paths that cannot enforce strong authentication.
- Limit OAuth access. Review applications and granted scopes, remove unnecessary permissions, and monitor for unusual third-party or application access.
- Make session recovery part of incident response. Document how to revoke sessions and tokens, how long they may remain valid, and how to verify that access has been withdrawn.
- Watch identity and data activity. Investigate unexpected sign-ins, resets, authentication-method changes, directory enumeration, and unusual mailbox or file access.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

