Glossary
Adversary-in-the-middle (AiTM) phishing
Phishing that proxies the real Microsoft sign-in page, relaying password and MFA to steal the resulting session cookie so the attacker can bypass MFA.
Adversary-in-the-middle (AiTM) phishing places a reverse proxy between the victim and the genuine sign-in service. The victim sees the real Microsoft sign-in page through the proxy, types their password and approves MFA; the proxy relays everything and keeps the session cookie Entra ID issues. The attacker then replays that cookie from their own machine and is not asked for MFA again.
In the logs, AiTM shows as an interactive sign-in from the proxy's network (often a hosting provider), followed by token replay: non-interactive sign-ins with the same Session ID from another IP or country. Phishing-resistant MFA (passkeys, FIDO2 keys, Windows Hello for Business) is the main defence. MITRE ATT&CK: T1557 and T1550.004.