Close-up of a laptop showing a sign-in screen with a password field

CybersecurityMicrosoft 365

What is password spraying? How it works and how to stop it

Password spraying is one of the attacks we have seen at our clients. It is quiet by design. An attacker tries one common password, such as “Spring2026!”, once against every email account in a company, waits an hour, then tries “Welcome1!” the same way.

No account gets more than a couple of wrong guesses, so nothing locks out and nobody gets an alert. It is cheap and still works, even against large organizations. Microsoft disclosed in 2024 that a nation-state group got into its corporate environment this way, starting with a single old test account that didn’t have multifactor authentication.

How a password spraying attack works

MITRE ATT&CK, a widely used catalog of attacker techniques, describes password spraying as using one password, or a small list of commonly used passwords, against many different accounts to avoid the lockouts that would happen if an attacker hammered one account with many guesses. A typical attack runs like this:

  1. The attacker collects usernames. Business email addresses usually follow a pattern like first.last@company.com, and names come from your website, LinkedIn and old breach data.
  2. They pick likely passwords: seasons and years, “Welcome1”, the company name with a number, the city or the local sports team. These often meet basic complexity rules while staying easy to guess.
  3. They spray slowly, trying one password across every account and waiting for lockout counters to reset before trying the next.
  4. They hide the source by spreading attempts across many IP addresses. In the Microsoft incident, attackers routed traffic through residential proxy networks so it blended in with normal users.
  5. They use the first account that works. One mailbox is enough to send convincing phishing to coworkers and clients, set up forwarding rules or look for invoices to redirect.

Spraying, brute force and credential stuffing compared

Three password attacks get mixed up often. The difference is how many passwords and how many accounts each one tries.

Woman taking notes at her desk beside a computer
AttackWhat it triesWhy it succeeds or fails
Brute forceMany passwords against one accountIt is noisy and usually stopped by lockout policies
Password sprayingA few common passwords against many accountsIt stays under lockout thresholds and needs only one person with a common password
Credential stuffingReal username and password pairs stolen from other breachesIt works when people reuse passwords across sites

All three end the same way, with someone signing in as one of your employees, and the same core control blocks all three: MFA.

Warning signs in your sign-in logs

Spraying leaves a pattern if someone is looking. In Microsoft 365, it shows up in the Microsoft Entra sign-in logs:

  • Failed sign-ins across many accounts in a short window, often with the same wrong password.
  • Sign-in attempts from countries or networks where you have no staff.
  • Attempts against accounts that don’t normally sign in, or names that don’t exist.
  • A successful sign-in followed by new inbox rules, mail forwarding or new MFA methods being registered.

Our email sign-in monitoring watches a mix of signals like these, and it has caught real takeover attempts at our clients. When it flags one, we contain the account within the hour.

99%+

of password spray attacks use legacy authentication protocols that can’t do MFA, according to Microsoft

Sprayers usually aren’t targeting you by name. They work through lists of email domains and take whatever succeeds, and smaller organizations are more likely to have the gaps that pay off: an account without MFA (often a shared mailbox, a former employee’s account or an exception made for the owner), an old copier or scanner still using basic authentication, complexity rules that push people toward Season+Year+!, and nobody watching the logs.

How to stop password spraying

Turn on MFA for every account

With MFA, a correct password isn’t enough to get in. Cover every user, including admins, shared mailboxes that allow sign-in and accounts that are rarely used. For our clients, admin accounts use phishing-resistant sign-in such as security keys or passkeys, and everyone else approves sign-ins in an app with number matching.

Block legacy authentication

Older protocols such as POP, IMAP and basic-auth SMTP can’t do MFA, so attackers use them to test passwords and get around your MFA policy. In Microsoft 365, security defaults or a Conditional Access policy can block them. Fix the scanner or old app that still depends on them first.

Ban the passwords sprayers try

Microsoft Entra Password Protection automatically blocks known weak passwords and their variations. With the right license you can add a custom list with your company name, city, products and other terms people tend to use. NIST’s current guidelines (SP 800-63B-4) call for checking new passwords against a blocklist of common and compromised values, requiring at least 15 characters when a password is the only factor, and not forcing periodic changes unless there’s evidence of compromise.

Give staff a password manager

A business password manager lets staff use long, unique passwords without memorizing them, which helps against both spraying and credential stuffing. Our guide on how password managers protect your accounts covers the details. Our clients get a managed one from us.

Keep lockout settings sensible

Microsoft Entra smart lockout is on by default and locks an account for one minute after 10 failed attempts, with longer lockouts after that. Microsoft recommends keeping the threshold at 10 or less and the lockout duration at least 60 seconds. Lockouts slow attackers down, but spraying is designed to stay under them, so treat them as a backstop.

If an account was sprayed successfully

Microsoft’s guidance covers the first three steps. The last two keep a takeover from turning into something larger:

  1. Reset passwords for the targeted accounts.
  2. Revoke active sessions for any account that was compromised.
  3. Block legacy authentication and require MFA.
  4. Check the compromised mailbox for forwarding rules and for messages sent to clients.
  5. Review what the account could reach, so you can decide whether any notification rules apply. Our post on data breach response covers that decision.

Spraying only pays off when one account has a common password and no MFA. Finding that account before an attacker does is everyday work for our cybersecurity services. Book an intro call and we’ll look for yours.

FAQ

Frequently asked questions

How do you prevent password spraying?

Turn on MFA for every account, including admins, shared mailboxes and rarely used accounts. Block legacy authentication such as POP, IMAP and basic-auth SMTP, which can’t do MFA. Ban the passwords sprayers try with Microsoft Entra Password Protection and a custom list of local terms, and give staff a password manager.

What is password spraying?

Password spraying is an attack where someone tries one common password, such as “Spring2026!”, against every account in a company, then waits and tries another. No single account gets enough wrong guesses to lock out, so nobody gets an alert. It needs only one person with a common password and no MFA.

How do you detect password spraying?

Look in the Microsoft Entra sign-in logs for failed sign-ins across many accounts in a short window, often with the same wrong password. Other signs are attempts from countries where you have no staff, attempts against accounts that don’t exist or rarely sign in, and a successful sign-in followed by new inbox rules, forwarding or MFA methods.

Sources: MITRE ATT&CK: Brute Force, Password Spraying (T1110.003); Microsoft Security Blog: Midnight Blizzard, guidance for responders, January 2024; Microsoft Learn: Block legacy authentication with Conditional Access; Microsoft Learn: Security defaults in Microsoft Entra ID; Microsoft Learn: Eliminate bad passwords using Microsoft Entra Password Protection; Microsoft Learn: Configure Microsoft Entra for Zero Trust, protect identities and secrets; Microsoft Learn: Alert classification for password spray attacks; NIST SP 800-63B-4: Digital Identity Guidelines, Authentication, 2025.

Talk to an advisor

Questions about your own environment?

Our team can walk through how this applies to your organization, with honest recommendations and no pressure.