Published:
Sep 24, 2026
|
Last updated:
Sep 24, 2026
|
7
min read

The New AI Threats Facing Microsoft 365 Tenants: What Security Teams Need to Watch

Andrew McAllister
Andrew is Vice President of APAC Sales at CoreView, bringing nearly 20 years of experience in enterprise technology, cyber security, and cloud software to help organisations across Asia Pacific strengthen Microsoft 365 governance, reduce risk, and build more resilient tenants.

One compromised admin account can hand an attacker the configuration layer of your Microsoft 365 tenant. AI has cut the time that takes from weeks to seconds, and most organisations will not see the changes until the damage is done.

In this article

Executive summary

An Iranian-aligned threat group breached Stryker by compromising admin credentials and abusing Microsoft Intune to wipe more than 200,000 devices worldwide.

The configuration layer of the M365 tenant is now the primary target, because control of it lets an attacker move through the environment unchecked and disable Defender on the way through.

MFA remains non-negotiable at the admin layer, though AI-driven attacks are already bypassing it, which puts configuration monitoring on equal footing as a control.

A workable defence stack has three layers: a known baseline, real-time drift detection, and fast rollback. Configuration backup matters as much as data backup, and almost nobody does it.

Why Microsoft 365 Attacks Now Move in Seconds Rather Than Weeks

Security teams have always known that their Microsoft environment is both their greatest asset and their greatest threat. It’s where their data and admin controls live, which means a single misconfiguration can easily become an open door for a bad actor.

But something has shifted in the last few years. The target of attacks hasn’t changed, but the speed and sophistication of the cyberattacks security teams have to deal with have.

In one recent example, an Iranian-aligned threat group breached medical technology giant Stryker by compromising admin credentials and abusing Microsoft’s own Intune device-management console, turning a tool built to protect endpoints into the mechanism that wiped them, across more than 200,000 devices worldwide.

What used to take a determined hacker weeks or even months can now happen in seconds. AI has entered the picture on both sides of a security breach, meaning it’s accelerating how attackers get in and escalating the damage they can cause once they are.

Here’s what organisations need to put in place now before they become the next international case study.

Why Attackers Now Target Your Microsoft 365 Configuration Layer

The Microsoft 365 (M365) tenant has evolved rapidly over the last 10 years. Today, it’s the digital heart of most organisations, home to your identity services, PII, and just about everything else. Previously, hackers might have been looking to steal your data, but now it’s the administrative configuration layer that’s a primary focus as that’s how they can cause even catastrophic financial pressure on organisations.

To get there, they’re often using techniques like OAuth consent phishing, man-in-the-middle attacks, or an old-fashioned phishing attack to compromise an admin account. Once they’re in, they’re looking to access the configuration layer. From there, hackers can move around the M365 tenant almost unchecked.

If this happens, you can almost guarantee that a sophisticated hacker will deploy AI scanners into your M365 environment. AI moves quickly and is also persistent. If a scanner gets shut down or blocked, another wave is simply released, and this continues until it finds what it needs, which is usually vulnerabilities to exploit, and those vulnerabilities sit at the configuration layer.

This is typically where we see organisations get confused. They think that because they’re signed up to a Microsoft service, Microsoft will keep the whole thing protected; in reality, it’s your responsibility to configure your M365 environment in a way that supports how your organisation runs.

Because every organisation has unique needs, this responsibility can create a multitude of permutations in how your M365 tenant can be configured. Different teams need different workflows and different layers of access, so no default set-up works for everyone. The same flexibility that supports your organisational productivity also opens the door for risk because it’s this configuration layer, the ‘seal’ of the tenant, that’s constantly being probed by external threats.

Legacy configurations that were never deployed properly or never revisited are a common culprit. They might have been fine out of the box five or more years ago, but that doesn’t mean they’re still fit for purpose; left unchecked, they’re a real risk.

Microsoft themselves know this is a problem and openly share that the number one security threat to their own ecosystem is bad or misconfigured environments, because without a secure set of configurations, an AI-driven hack will find the gaps quickly.

How One Compromised Admin Account Opens Your Entire Tenant

If you were manually trying to work your way through an organisation, admin accounts are the most valuable target. We’re seeing a range of ways that hackers are operating to obtain these targets.

They can go on the dark web and buy admin credentials for almost any organisation, and it doesn’t cost much these days. For the biggest organisations, a hacker might spend a couple hundred thousand dollars to get a global admin account to a highly sensitive tenant. But in the grand scale of things, if they obtain global admin access for a large bank, they can hold that for ransom worth far more than a couple hundred thousand.

Sophisticated AI-created phishing methods are also becoming increasingly problematic, and people are being subjected to techniques they haven’t encountered before. AI can build a profile to phish someone roughly four or five times quicker than a hacker gathering all those details manually.

Voice phishing is quickly becoming a powerful way to accelerate an admin account breach. Traditional phishing has been around for so long that there’s now a lot of general cyber awareness around it and ongoing cybersecurity team efforts to educate across organisations. Voice phishing is where AI bots call an IT admin and keep them on the phone long enough to capture a voice imprint. Once they’ve got that imprint, the same AI bot can call the organisation’s help desk and sound exactly like that admin: “I've lost my admin account, I've been locked out of the system, can you help me reset it?”

However they obtain the admin access, the point is it’s less about volume and more about efficacy in getting hold of an admin account, and it’s only one account they need.

Why MFA Alone No Longer Stops AI-Driven Attacks on Admin Accounts

At CoreView we’re often surprised that some of the organisations we assess still aren’t properly enforcing multi-factor authentication (MFA) at their administration layer. Basic MFA controls, especially for admin accounts, remain a non-negotiable first step in all security measures.

But MFA is no longer the finish line in the same way it might have been a few years ago. We’ve seen sophisticated AI-driven attacks compromise multi-factor authentication itself. It’s still a critical layer of defence, but it has weaknesses, and sophisticated attackers are learning to bypass it.

So what’s left when MFA fails, and someone’s already inside your M365 tenant making changes? The answer is configuration monitoring. If MFA is the front door, configuration is everything that happens once someone’s already through it, and that’s where the real damage tends to happen.

This is where it's important to ask: who’s defending Defender?

Microsoft Defender’s job is to monitor for critical security incidents, but if a hacker gains admin-level access, Defender’s settings are part of the configuration level that they now potentially have access to. From there they can make any changes they want to allow them to keep moving through the tenant, or disable Defender altogether.

This is why configuration monitoring matters just as much as MFA. Configurations that have been built over decades can be unravelled in seconds with a sophisticated AI attack, and the scary part is that most organisations won’t see the changes until the damage is already done.

At CoreView, our stance is that you still need every traditional defence mechanism in place, including MFA, but you also need the ability to detect and respond at the configuration layer, because that’s where the most damage happens once the front door’s been breached.

The Three-Layer Defence Stack That Matches AI-Era Tenant Threats

There are three layers that we recommend as a critical defence stack that can help match the threat now facing organisations: know your baseline, detect drift, and rewind fast.

Step One, Know Your Microsoft 365 Configuration Baseline

Know what good looks like for your M365 tenant. This is what lets you recognise when something drifts away from it.

Step Two, Detect Configuration Drift in Real Time

When drift happens, you need to be able to catch it in real time. Detecting the issue and, ideally, the breach itself as it happens is what allows you to get ahead of it proactively before something worse happens.

Step Three, Rewind Your Tenant to a Known Good State

Once drift is detected, you need to be able to rewind to that ‘good state’ quickly and effectively. Catching a configuration change early and reversing it fast is what separates getting ahead of a breach from responding to one after it's happened.

It’s worth noting here that even with this defence stack in place, a determined hacker might still be able to find a way through and you’ll still be subject to a tenant takedown or ransom scenario. That’s why you need a backup.

Everyone thinks about backing up their data across email, OneDrive files, and SharePoint, but almost nobody backs up the configuration and settings of the tenant itself. This matters a lot more than you might think.

Think of it like a glass of water. Once the glass shatters and the water’s gone, no amount of scrambling can get it back in the glass. A tenant works the same way. Once it’s taken down, you can’t recover it by acting fast in the moment. Your backup strategy needs to cover the full configuration of your M365 environment, not just the data sitting inside it.

The organisations that avoid becoming the next Stryker case study aren’t those that never get hit. They’re the ones who know it can happen to them, put the measures in place to shut it down fast when it does, and recover quickly.

Strengthen Your Microsoft 365 Configuration Security With CoreView

Most organisations don’t know what ‘good’ looks like for their M365 configuration until something’s already gone wrong, and by then, it’s too late to ask.

The first step is visibility.

Get an assessment of your current configuration posture or start a conversation with the CoreView team about what a good configuration baseline looks like for your tenant. It’s a conversation worth having.

Get a personalized demo today

Created by M365 experts, for M365 experts.