Microsoft 365 MX spoofing mitigation guidance
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Microsoft issued mitigation guidance for Microsoft 365 tenants exposed to MX spoofing, because misconfigured mail routing can make phishing emails look internal and raise account compromise risk. The company told organizations to point MX records directly to Office 365, apply strict DMARC, and verify any third-party services tied to MX routing. Microsoft also recommended phishing-resistant MFA for privileged roles in Microsoft Entra ID. The guidance applies to tenants with custom routing not pointed to Office 365 and is meant to reduce credential theft, BEC, and fraud.
Related Happenings
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/Service
H score26
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/ServiceAbout this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
Campaign
H score37
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
CampaignAbout this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
Microsoft My Sign-Ins MFA outage
Service Disruption
H score25
First: 01.06.2026 14:40
Last: 01.06.2026 14:40
Sources 1
About this happening:
Microsoft is dealing with an ongoing outage that is blocking some users from setting up multi-factor authentication (MFA) and accessing My Sign-Ins. Affected users...
Microsoft My Sign-Ins MFA outage
Service DisruptionAbout this happening: Microsoft is dealing with an ongoing outage that is blocking some users from setting up multi-factor authentication (MFA) and accessing My Sign-Ins. Affected users...
Microsoft Exchange Server spoofing/XSS flaw under active exploitation (CVE-2026-42897)
Vulnerability
H score37
First: 15.05.2026 09:19
Last: 15.05.2026 09:19
Sources 1
About this happening:
CVE-2026-42897 is an actively exploited spoofing vulnerability in on-premises Microsoft Exchange Server that can lead to arbitrary JavaScript execution in a br...
Microsoft Exchange Server spoofing/XSS flaw under active exploitation (CVE-2026-42897)
VulnerabilityAbout this happening: CVE-2026-42897 is an actively exploited spoofing vulnerability in on-premises Microsoft Exchange Server that can lead to arbitrary JavaScript execution in a br...
Latest development: 09.06.2026 20:57
Microsoft identifies CVE-2026-42897 in Microsoft Exchange Server as an actively exploited spoofing vulnerability that can lead to JavaScript execution in a target’s browser when a specially crafted email is opened in Outlook Web Access under certain interaction conditions. Microsoft says mitigations are being pushed through the Exchange Emergency Mitigation Service while it continues work on the full update.
Microsoft Exchange Online blocks legacy TLS for POP3 and IMAP4 starting July 2026
Security Tool/Service
H score11
First: 28.04.2026 16:18
Last: 28.04.2026 16:18
Sources 1
About this happening:
Microsoft will block TLS 1.0 and TLS 1.1 for POP3/IMAP4 access to Exchange Online in July 2026, which could break legacy mail clients and embedded devices...
Microsoft Exchange Online blocks legacy TLS for POP3 and IMAP4 starting July 2026
Security Tool/ServiceAbout this happening: Microsoft will block TLS 1.0 and TLS 1.1 for POP3/IMAP4 access to Exchange Online in July 2026, which could break legacy mail clients and embedded devices...
Timeline
-
08.01.2026 16:01 2 articles · 6mo ago
Microsoft issues MX spoofing mitigation guidance for Microsoft 365 tenants
Mitigation Patch UpdateMicrosoft advised Microsoft 365 tenants with custom email routing to point MX records directly to Office 365, apply strict DMARC, verify any third-party services linked to MX, and enforce phishing-resistant MFA for privileged roles in Microsoft Entra ID to reduce internal-looking phishing and account compromise risk.
Show sources
- Phishing Attacks Exploit Misconfigured Email Routing Settings to Target Microsoft 365 Users — www.infosecurity-magazine.com — 08.01.2026 16:01
- Phishing Attacks Exploit Misconfigured Email Routing Settings to Target Microsoft 365 Users — www.infosecurity-magazine.com — 08.01.2026 16:01