Include:
Tech
Cybersecurity
Business Strategy
Channel Insights
Stay Connected
Acer America
Acer America Corp. is a computer manufacturer of business and consumer PCs, notebooks, ultrabooks, projectors, servers, and storage products.

Location

333 West San Carlos Street
San Jose, California 95110
United States

WWW: acer.com

ChannelPro Network Awards

hello 2
hello 3

News & Articles

July 20, 2026 |

Azure CLI attacks reveal major identity gap that MSPs might miss

Azure CLI password spray attacks are exposing gaps in MFA and Conditional Access. Frank Merino of Forthright Technology Partners explains what MSPs should do next.

A spike in Azure CLI password spray attacks is giving MSPs another reason to question whether multifactor authentication (MFA) is truly enforced across every customer login path.

As first reported by Steve Zurier of SCWorld, Huntress researchers observed more than 81 million login attempts targeting Microsoft Azure’s command-line interface between June 12 and June 26. The campaign compromised 78 user accounts across 64 organizations.

Huntress also reported a 155-fold increase in credential spray volume over the previous six months.

For MSPs, the bigger concern is not Azure CLI alone. It is the number of authentication paths attackers can test with stolen credentials until they find one that is not fully protected.

“This isn’t a new problem,” said Frank Merino, chief technology officer of Florida-based Forthright Technology Partners. “We’re seeing massive volumes of compromised credentials being leveraged in attacks, and from an MSP perspective, that’s the real lesson here.

“The issue isn’t necessarily a new attack technique. It’s that attackers continue to succeed by exploiting weaknesses in identity and access controls.”

Why Azure CLI password spray attacks matter to MSPs

Frank Merino

Frank Merino

Password spraying allows attackers to test commonly used or compromised passwords across large numbers of accounts. Unlike brute-force attacks against one user, password spraying distributes login attempts across many identities to reduce the chance of triggering account lockouts.

The Azure CLI password spray campaign highlights how legitimate Microsoft tools and authentication methods can become attack paths when identity policies do not apply consistently.

Attackers do not always need to exploit a software vulnerability. They may only need a valid username, a reused password and an authentication flow that does not trigger additional verification.

“Many of these attacks aren’t breaking through sophisticated defenses,” Merino explained. “They’re walking through the front door using valid credentials.”

Conditional Access does not automatically mean MFA

MSPs have spent years helping customers deploy MFA across Microsoft 365 and Azure environments. Microsoft Entra ID Conditional Access often plays a central role in those deployments.

However, that Conditional Access should not be confused with MFA itself, Merino cautioned. “It’s a policy engine that evaluates conditions and determines what controls should be applied.”

Conditional Access can require MFA based on the user, application, device or location. But it only protects authentication methods that the policy explicitly covers.

Organizations may cite Conditional Access during audits as proof that they enforce MFA. In reality, gaps may still leave some accounts, applications or login flows unprotected.

“As the saying goes, ‘identity is the new firewall,’” Merino said. “Conditional Access is one of the primary ways to enforce and strengthen that identity perimeter.”

How MFA gaps leave Microsoft environments exposed

The Azure CLI campaign reportedly targeted the resource owner password credentials flow, commonly known as ROPC. This legacy authentication flow sends a username and password directly to a token endpoint.

Because ROPC does not use the same interactive login process as a browser-based sign-in, it can bypass the authentication layer that normally triggers MFA.

That leaves organizations with MFA enabled but not consistently enforced across every login attempt.

“What we’ve learned over the last several years is that simply enabling MFA isn’t enough,” Merino noted. “Attack volumes haven’t declined. In many cases they’ve increased.”

The reasons can include weak MFA methods, policy exceptions and Conditional Access rules that allow some scenarios without additional verification.

Token theft and other identity-based attack techniques create additional risk. “Attackers have adapted, and defenders need to do the same,” Merino said.

MSPs must move beyond checkbox compliance

The Azure CLI password spray attacks show why MSPs cannot treat identity security as a one-time project or a compliance checklist item.

MSPs need to test identity controls across users, applications and authentication methods. They also need to identify policy exclusions and understand why each exception exists.

“MSPs need to look beyond checkbox compliance and truly understand the security posture of their customers’ environments,” Merino said. “Credentials, identities, tokens and external-facing access points need to be treated with a high degree of scrutiny.”

That level of scrutiny may be difficult for smaller providers that lack dedicated identity security expertise.

“If an MSP doesn’t have the expertise to evaluate those risks thoroughly, partnering with organizations that do is often the right decision,” Merino said. “Customers deserve that level of diligence.”

Merino said that Forthright Technology Partners has developed processes to evaluate the different Conditional Access scenarios users may encounter.

“The goal is to identify gaps, understand the associated risks and present those risks clearly to customers so they can make informed decisions,” Merino added. “Ultimately, it’s their environment and their business risk, but it’s our responsibility to ensure that they understand the implications of those choices.”


10 steps MSPs can take to reduce Azure identity risk

MSPs should use the campaign as an opportunity to review identity controls across every managed Microsoft environment.

1. Audit Conditional Access policies.
Review which users, applications and authentication types are covered. Look for exclusions, report-only policies and rules that do not require MFA.
2. Test every authentication path.
Confirm how policies behave across browsers, mobile apps, command-line tools and legacy protocols.
3. Restrict Azure CLI access.
Limit Azure CLI use to approved technical roles with a documented business need.
4. Block legacy authentication flows.
Disable or tightly restrict ROPC and other legacy methods wherever possible.
5. Use stronger MFA methods.
Move customers toward phishing-resistant options such as passkeys, security keys or certificate-based authentication.
6. Review policy exceptions.
Reassess exclusions for executives, service accounts, emergency accounts and legacy applications.
7. Monitor compromised credentials.
Force password resets when credentials appear in breach data and block known weak passwords.
8. Watch post-login behavior.
Monitor unusual application access, privilege changes and other activity after authentication succeeds.
9. Inventory exposed services.
Identify which applications and tools accept customer credentials from the internet.
10. Document customer risk decisions.
Clearly explain identified gaps, recommended fixes and the consequences of declining remediation.

Scale and complexity make identity security harder

The security concepts are not new. MSPs have embraced least privilege, zero trust and strong access hygiene for years, but they still struggle to apply them consistently across distributed customer environments.

“The challenge isn’t that these concepts are difficult to understand; it is scale and complexity,” Merino said.

“Environments are more distributed than ever, identities exist across countless services, and MSPs must manage those risks across dozens or even hundreds of customers,” he added. “That complexity creates opportunities for gaps that attackers are eager to exploit.”

Azure CLI is only one example. Similar gaps can appear in third-party applications, service accounts and remote access tools.

“The Azure CLI issue referenced in the article is simply another example of threat actors leveraging legitimate external-facing capabilities, compromised credentials and increasingly sophisticated techniques — including AI-assisted automation — to bypass weak controls,” Merino said.

“Whether it’s Azure CLI, Conditional Access misconfigurations, Fortinet vulnerabilities or the next headline-making exploit, the underlying principles remain the same: least privilege, zero trust, minimizing exposed services and maintaining strong security hygiene.”

Identity security affects trust in the MSP model

Small and midsized businesses (SMBs) often don’t have in-house security teams. So, they depend on MSPs.

“A 15-person CPA firm, an 80-person property management company or a growing local business doesn’t have the resources to maintain a deep cybersecurity team,” Merino said. “MSPs fill that gap and enable those organizations to operate securely and compete effectively.”

That dependence raises the stakes when identity controls fail.

“These attacks don’t target one MSP,” Merino said. “They target the customers we all serve. If enough organizations fall victim to preventable identity-based attacks, the damage extends beyond a single provider. It erodes trust in the MSP industry as a whole.”

MSPs should share lessons, strengthen their practices and help customers understand that identity security requires continuous attention, Merino said. “My perspective is simple: MSPs need to educate themselves, educate their customers and work together as a community.

“Protecting customers isn’t just about protecting our individual businesses. It’s about maintaining trust in the MSP model itself.”


Jonathan Browning is executive director of content and engagement for The ChannelPro Network. He has been a leader in the IT channel for close to a decade. He’s an avid fan and early adopter of technology. He believes that the managed services industry is the most important driver of economic growth and human innovation in today’s world.

Images: Photo Agency – stock.adobe.com, Frank Merino

Related News & Articles

Free MSP Resources

Editor’s Choice


Explore ChannelPro

Events

Reach Our Audience