Phishing used to be fairly easy to picture: a dodgy email, a suspicious attachment and somebody asking for your password. That still happens, but the more useful way to think about phishing now is account takeover.
The attacker is usually trying to get into something valuable, often Microsoft 365, email or another cloud service. Once they are in, they may be able to read conversations, impersonate team members, reset passwords, change payment details or use the compromised account to target somebody else.

MFA still matters, but the configuration matters too
Multi-factor authentication is still one of the most useful controls a business can put in place. A stolen password is much less useful when the attacker also needs another factor.
The mistake is treating “MFA enabled” as the end of the conversation. Different authentication methods provide different levels of protection, and the policies around them still need to be configured properly.
What is MFA fatigue?
MFA fatigue is when an attacker already has a password and repeatedly triggers approval prompts, hoping the user eventually approves one just to make the notifications stop. Sometimes the attacker also contacts the user and pretends to be IT or Microsoft support.
An unexpected MFA prompt should be treated as a warning, not an annoyance. If you did not just try to sign in, deny the request and report it.

Photo by Vitaly Gariev via Unsplash.
Number matching helps reduce accidental approvals
Microsoft Authenticator number matching makes the person signing in enter the number shown on the login screen rather than simply tapping Approve. It is not a complete answer to phishing, but it makes blind approval much harder.
Phishing-resistant authentication is worth considering for higher-risk accounts
For administrators and other higher-risk users, stronger authentication methods can reduce the chance of credentials being replayed through a fake sign-in page. Depending on the environment, that can include passkeys, security keys or Windows Hello for Business.
This does not mean every small business needs to replace every login method tomorrow. It means the most sensitive accounts should not automatically receive the weakest acceptable option just because it is convenient.
Business email compromise is usually about trust, not malware
One of the more damaging outcomes of an email account takeover is business email compromise. The attacker may sit quietly in a mailbox, learn how invoices or payments are handled, then step into a real conversation at the point where money is about to move.
This is why a convincing email is not enough evidence for an important payment change. If a supplier suddenly changes bank details, or an executive asks for an unusual transfer, verify it using a known phone number or another trusted channel rather than replying to the same email thread.

Photo by Brett Jordan via Unsplash.
Team members should know the few warning signs that actually matter
Security awareness works better when people are given a small number of useful habits rather than a giant list of things to remember.
Unexpected sign-in prompts, password reset messages you did not request, urgent payment changes, unusual requests for sensitive information and links that take you to a sign-in page should all be treated carefully. If something feels unusual, contact the person or provider separately instead of continuing through the message.
What should the IT provider be doing behind the scenes?
The user should not carry the whole security process. There should also be technical controls around the account and the wider Microsoft 365 environment.
That normally means making sure MFA is actually enforced where it should be, reviewing authentication methods, limiting administrative access, using Conditional Access where appropriate, monitoring useful sign-in and security alerts, securing email, removing old accounts and having a clear process for dealing with a suspected compromise.
This also ties back to the Essential Eight. MFA is one control, but account protection is stronger when it sits alongside patching, application control, restricted privileges and the other controls around the environment.
If an account may already be compromised, a password reset is not always enough
If somebody has approved an unexpected MFA request, entered credentials into a suspicious site or noticed unusual mailbox activity, deal with it as an incident rather than simply changing the password and moving on.
The account may need active sessions revoked, authentication methods reviewed, mailbox forwarding and rules checked, sign-in activity investigated and connected applications reviewed. If money may have been redirected, contact the bank immediately as well.
The useful goal is to make one mistake less damaging
People will occasionally click the wrong thing. A useful security setup assumes that can happen and puts more than one layer between a mistake and a serious incident.
Good MFA, sensible authentication policies, email protection, monitoring and straightforward team members verification processes all help. None of them need to be complicated for the sake of it.
If you want a clearer view of how well your Microsoft 365 and identity controls are actually configured, Q10 can review the current environment, identify the important gaps and work through improvements in sensible stages. You can also read our broader guide to cybersecurity for small businesses or see how Q10 approaches cybersecurity services.