Problem
Microsoft 365 can be configured well, but default settings and partial MFA rollouts leave gaps attackers can exploit with QR codes, fake login prompts, and token theft.
Why it matters in 2026
QR phishing moves the attack from a monitored workstation to a personal or mobile device where controls, visibility, and user suspicion are weaker.
Who this affects
- Small businesses using Microsoft 365.
- Teams with email-heavy approval or invoice workflows.
- Owners who assume MFA alone blocks phishing.
Step-by-step recipe
- Confirm MFA is enforced for every user and administrator.
- Review administrator accounts separately from normal users.
- Use phishing-resistant options where practical.
- Train users to treat QR login prompts as high risk.
- Review sign-in logs for unfamiliar devices and unusual locations.
- Document who can reset MFA and approve access changes.
Common mistakes
- Assuming QR codes are safer than links.
- Leaving legacy authentication or weak recovery paths enabled.
- Not reviewing admin consent and OAuth app approvals.
Downloads and next steps
DIY next step
Pick one tenant administrator account and verify how it is protected before reviewing the rest of the tenant.
CyberHouse CTA
Want us to handle this for you? CyberHouse can help with Microsoft 365 protection, cyber risk cleanup, ransomware readiness, secure automation, and vendor-ready cyber baseline work.
Visit CyberHouse