Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Learn how to build bypass-resistant security beyond traditional passkey implementations in this 20-minute conference session from Microsoft Ignite 2025. Explore real-world bypass attack examples including incidents at Uber and MGM, then discover how attackers exploit vulnerabilities in help desk operations, enrollment processes, and self-service recovery systems to circumvent multi-factor authentication entirely. Examine the collaboration between RSA and Microsoft to secure the complete credential lifecycle and identify critical blind spots that threat actors commonly target. Watch a comprehensive demonstration of secure MFA enrollment and identity proofing processes, including password reset procedures through company verification URLs and authentication via conditional access policies. Gain insights into building a comprehensive security posture that addresses both phishing resistance and bypass resistance, with practical strategies for protecting against sophisticated social engineering attacks that target organizational weak points beyond technical authentication mechanisms.
Syllabus
0:00 - Examples of Bypass Attacks: Uber, MGM, and Others
00:07:46 - Summary of Bypass Attack Points
00:07:56 - Transition to Demonstration
00:08:06 - Demo: Secure MFA Enrollment and ID Proofing
00:15:02 - Admin instructs user to visit company verification URL for password reset
00:15:37 - User begins authentication via conditional access policies
00:15:57 - Discussion on secure and convenient multi-factor authentication options
Taught by
Microsoft Ignite