threat_intelligence1082 wordsRead on Arc Codex

When identity is compromised, seconds matter

When identity is compromised, seconds matter Barracuda Managed XDR now includes Automated Threat Response for Duo, helping contain identity-based attacks automatically before they spread. Key takeaways - Multifactor authentication (MFA) is essential, but attackers are increasingly using tactics like MFA fatigue, session hijacking and enrollment hijacking to get around it. - Once identity is compromised, attackers can move quickly across cloud apps, email, files, and administrative systems. - Manual response often takes too long to contain identity-based attacks before damage spreads. - Barracuda Managed XDR with Automated Threat Response for Duo helps contain identity-based attacks by automatically disabling compromised accounts in seconds. Barracuda Managed XDR now includes Automated Threat Response (ATR) for Duo, enabling instant, hands-free containment when identity compromise is detected. It is the first identity-focused ATR capability in our XDR portfolio, and it changes the math on how quickly organizations can respond when attackers target the identity layer. But to understand why this matters, you need to understand what happens when attackers go after multifactor authentication (MFA) and what they can do once they bypass it. MFA is not impenetrable Your organization deployed multifactor authentication. You enforced it across Microsoft 365, Salesforce, your VPN, and every other cloud application your employees touch. You did the right thing. MFA remains one of the most effective defenses against credential-based attacks. But attackers have adapted. They have developed techniques specifically designed to bypass, exploit or simply exhaust the humans on the other side of that push notification. How attackers get past MFA Before an attacker can exploit MFA, they need credentials. Getting the attackers’ hands on these is often easier than IT teams want to believe. Credentials leak through phishing campaigns, infostealer malware, password reuse from breached databases, or social engineering. Once an attacker has a valid username and password, the MFA prompt is the only thing standing between them and your environment. Here is how they get past it: MFA fatigue The attacker repeatedly attempts to log in, triggering push notification after push notification on the legitimate user’s phone. At 7 am. At 11 pm. During meetings. During dinner. The user’s phone buzzes relentlessly. Eventually, out of frustration, confusion or just to make it stop, the user taps “Approve.” The attacker is in. Session hijacking The user receives an email that looks like a legitimate Microsoft 365 login page. They enter their credentials, complete MFA and see a brief loading screen before being redirected to their normal inbox. Everything seems fine. But the page was a proxy controlled by the attacker. In the background, the attacker captured the session token that Microsoft issued after the user authenticated. Now the attacker pastes that token into their own browser — in another city, another country — and they are logged in as the user. No password needed. No MFA prompt. The system thinks they already authenticated. MFA enrollment hijacking The attacker calls your help desk. “Hi, this is Sarah from accounting. I just got a new phone, and I cannot get into my email. Can you help me re-enroll in MFA?” If your help desk verifies identity by asking questions an attacker could easily research (i.e., manager’s name, employee ID, last four of a phone number) they may reset the MFA enrollment. The attacker registers their own device. Now every time they log in, the push notification goes to their phone. They approve themselves. What happens when identity is compromised In most organizations, the identity provider sits in front of the entire cloud estate: Microsoft 365, Salesforce, VPN, HR systems, cloud consoles, etcetera. The attacker authenticated once, and the identity provider vouched for them everywhere. The attacker takes action. Now the damage begins: Inbox rules forward sensitive emails to external addresses. Files disappear from SharePoint. Messages go out requesting wire transfers that look completely legitimate because they come from a real, authenticated user. And, if the account has admin privileges, the attacker creates backdoor accounts, disables security controls and escalates to systems they could not reach before. All of this happens in minutes. Every minute the account stays active, the blast radius expands. The problem with manual response Traditional security operations follow a predictable sequence: An alert fires, lands in a queue, gets reviewed, investigated, escalated, and eventually someone with the right permissions disables the account. How long does that take? Fifteen minutes? Maybe. If you are lucky. An hour or two if the alert fires outside business hours. Longer if the analyst needs to track down someone with admin access. Meanwhile, the attacker is working. The math doesn’t work. Manual response cannot keep pace with automated attacks. Automated Threat Response: Containment in seconds This is why we built ATR for Duo in Barracuda Managed XDR. It continuously monitors identity activity: logins from anomalous locations, MFA manipulation and user-reported fraudulent pushes. It correlates those signals with cloud and SaaS activity across Microsoft 365, Google Workspace, AWS, Azure, Entra ID, and other identity providers like Okta. When the evidence points to compromise, ATR acts. Automatically. The affected account is disabled in seconds, not hours. No ticket. No escalation. No waiting for someone to wake up and check their phone. The attacker is locked out before they can persist, escalate privileges or move laterally. And ATR does not stop at Duo. When Barracuda Managed XDR detects account takeover in Microsoft 365 or Google Workspace, it can automatically disable the compromised account, revoke active sessions and block malicious sign-ins, providing hands-free containment across both identity providers and cloud platforms where attackers focus their efforts. Seconds matter MFA remains one of the most important controls you can deploy. But attackers have adapted, and organizations that assume MFA alone will protect them are the ones most vulnerable when it does not. The difference between a contained incident and a catastrophic breach often comes down to response time. Barracuda Managed XDR with ATR for Duo closes that gap. Detection and response happen automatically, at machine speed, before attackers can capitalize on their access. Identity threats are not going away. But with the right detection and response capabilities in place, you can outflank the attackers who think they have already won. 2026 Email Threats Report Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected Subscribe to the Barracuda Blog. Sign up to receive threat spotlights, industry commentary, and more. The Managed XDR Global Threat Report Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.