Sub-technique of T1556 Modify Authentication Process.View on attack.mitre.org
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Once adversaries have gained access to a network by either compromising an account lacking MFA or by employing an MFA bypass method such as Multi-Factor Authentication Request Generation, adversaries may leverage their access to modify or completely disable MFA defenses. This can be accomplished by abusing legitimate features, such as excluding users from Azure AD Conditional Access Policies, registering a new yet vulnerable/adversary-controlled MFA method, or by manually patching MFA programs and configuration files to bypass expected functionality.
For example, modifying the Windows hosts file (`C:\windows\system32\drivers\etc\hosts`) to redirect MFA calls to localhost instead of an MFA server may cause the MFA process to fail. If a "fail open" policy is in place, any otherwise successful authentication attempt may be granted access without enforcing MFA.
Depending on the scope, goals, and privileges of the adversary, MFA defenses may be disabled for individual accounts or for all accounts tied to a larger group, such as all domain accounts in a victim's network environment.
Rules on DetectionCode tagged with T1556.006.
| Rule | Level | Log source |
|---|---|---|
| Disabling Multi Factor Authentication | high | m365 / NULL |
| Okta MFA Reset or Deactivated | medium | okta / NULL |
| Azure AD Only Single Factor Authentication Required | low | azure / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ASL AWS Multi-Factor Authentication Disabled | TTP | NULL | ASL AWS CloudTrail |
| ASL AWS New MFA Method Registered For User | TTP | NULL | ASL AWS CloudTrail |
| AWS Multi-Factor Authentication Disabled | TTP | NULL | AWS CloudTrail DeleteVirtualMFADevice, AWS CloudTrail DeactivateMFADevice |
| AWS New MFA Method Registered For User | TTP | NULL | AWS CloudTrail CreateVirtualMFADevice |
| Azure AD Multi-Factor Authentication Disabled | TTP | NULL | Azure Active Directory Disable Strong Authentication |
| Azure AD New MFA Method Registered For User | TTP | NULL | Azure Active Directory User registered security info |
| GCP Multi-Factor Authentication Disabled | TTP | NULL | Google Workspace |
| Okta Multi-Factor Authentication Disabled | TTP | NULL | Okta |
| PingID Mismatch Auth Source and Verification Response | TTP | NULL | PingID |
| PingID New MFA Method After Credential Reset | TTP | NULL | PingID |
| PingID New MFA Method Registered For User | TTP | NULL | PingID |
| Used by | Procedure example |
|---|---|
| GroupScattered Spider | After compromising user accounts, Scattered Spider registers their own MFA tokens. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | The AADInternals `Set-AADIntUserMFA` command can be used to disable MFA for a specified user. |
| MalwareSLOWPULSE | SLOWPULSE can insert malicious logic to bypass RADIUS and ACE two factor authentication (2FA) flows if a designated attacker-supplied password is provided. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries modified two-factor settings within the FortiGate solution to `unset`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.