Password spraying is one of the attacks we have seen at our clients. It is quiet by design. An attacker tries one common password, such as “Spring2026!”, once against every email account in a company, waits an hour, then tries “Welcome1!” the same way.
No account gets more than a couple of wrong guesses, so nothing locks out and nobody gets an alert. It is cheap and still works, even against large organizations. Microsoft disclosed in 2024 that a nation-state group got into its corporate environment this way, starting with a single old test account that didn’t have multifactor authentication.
How a password spraying attack works
MITRE ATT&CK, a widely used catalog of attacker techniques, describes password spraying as using one password, or a small list of commonly used passwords, against many different accounts to avoid the lockouts that would happen if an attacker hammered one account with many guesses. A typical attack runs like this:
- The attacker collects usernames. Business email addresses usually follow a pattern like first.last@company.com, and names come from your website, LinkedIn and old breach data.
- They pick likely passwords: seasons and years, “Welcome1”, the company name with a number, the city or the local sports team. These often meet basic complexity rules while staying easy to guess.
- They spray slowly, trying one password across every account and waiting for lockout counters to reset before trying the next.
- They hide the source by spreading attempts across many IP addresses. In the Microsoft incident, attackers routed traffic through residential proxy networks so it blended in with normal users.
- They use the first account that works. One mailbox is enough to send convincing phishing to coworkers and clients, set up forwarding rules or look for invoices to redirect.
Spraying, brute force and credential stuffing compared
Three password attacks get mixed up often. The difference is how many passwords and how many accounts each one tries.

| Attack | What it tries | Why it succeeds or fails |
|---|---|---|
| Brute force | Many passwords against one account | It is noisy and usually stopped by lockout policies |
| Password spraying | A few common passwords against many accounts | It stays under lockout thresholds and needs only one person with a common password |
| Credential stuffing | Real username and password pairs stolen from other breaches | It works when people reuse passwords across sites |
All three end the same way, with someone signing in as one of your employees, and the same core control blocks all three: MFA.
Warning signs in your sign-in logs
Spraying leaves a pattern if someone is looking. In Microsoft 365, it shows up in the Microsoft Entra sign-in logs:
- Failed sign-ins across many accounts in a short window, often with the same wrong password.
- Sign-in attempts from countries or networks where you have no staff.
- Attempts against accounts that don’t normally sign in, or names that don’t exist.
- A successful sign-in followed by new inbox rules, mail forwarding or new MFA methods being registered.
Our email sign-in monitoring watches a mix of signals like these, and it has caught real takeover attempts at our clients. When it flags one, we contain the account within the hour.
99%+
of password spray attacks use legacy authentication protocols that can’t do MFA, according to Microsoft
Sprayers usually aren’t targeting you by name. They work through lists of email domains and take whatever succeeds, and smaller organizations are more likely to have the gaps that pay off: an account without MFA (often a shared mailbox, a former employee’s account or an exception made for the owner), an old copier or scanner still using basic authentication, complexity rules that push people toward Season+Year+!, and nobody watching the logs.
How to stop password spraying
Turn on MFA for every account
With MFA, a correct password isn’t enough to get in. Cover every user, including admins, shared mailboxes that allow sign-in and accounts that are rarely used. For our clients, admin accounts use phishing-resistant sign-in such as security keys or passkeys, and everyone else approves sign-ins in an app with number matching.
Block legacy authentication
Older protocols such as POP, IMAP and basic-auth SMTP can’t do MFA, so attackers use them to test passwords and get around your MFA policy. In Microsoft 365, security defaults or a Conditional Access policy can block them. Fix the scanner or old app that still depends on them first.
Ban the passwords sprayers try
Microsoft Entra Password Protection automatically blocks known weak passwords and their variations. With the right license you can add a custom list with your company name, city, products and other terms people tend to use. NIST’s current guidelines (SP 800-63B-4) call for checking new passwords against a blocklist of common and compromised values, requiring at least 15 characters when a password is the only factor, and not forcing periodic changes unless there’s evidence of compromise.
Give staff a password manager
A business password manager lets staff use long, unique passwords without memorizing them, which helps against both spraying and credential stuffing. Our guide on how password managers protect your accounts covers the details. Our clients get a managed one from us.
Keep lockout settings sensible
Microsoft Entra smart lockout is on by default and locks an account for one minute after 10 failed attempts, with longer lockouts after that. Microsoft recommends keeping the threshold at 10 or less and the lockout duration at least 60 seconds. Lockouts slow attackers down, but spraying is designed to stay under them, so treat them as a backstop.
If an account was sprayed successfully
Microsoft’s guidance covers the first three steps. The last two keep a takeover from turning into something larger:
- Reset passwords for the targeted accounts.
- Revoke active sessions for any account that was compromised.
- Block legacy authentication and require MFA.
- Check the compromised mailbox for forwarding rules and for messages sent to clients.
- Review what the account could reach, so you can decide whether any notification rules apply. Our post on data breach response covers that decision.
Spraying only pays off when one account has a common password and no MFA. Finding that account before an attacker does is everyday work for our cybersecurity services. Book an intro call and we’ll look for yours.
FAQ
Frequently asked questions
How do you prevent password spraying?
Turn on MFA for every account, including admins, shared mailboxes and rarely used accounts. Block legacy authentication such as POP, IMAP and basic-auth SMTP, which can’t do MFA. Ban the passwords sprayers try with Microsoft Entra Password Protection and a custom list of local terms, and give staff a password manager.
What is password spraying?
Password spraying is an attack where someone tries one common password, such as “Spring2026!”, against every account in a company, then waits and tries another. No single account gets enough wrong guesses to lock out, so nobody gets an alert. It needs only one person with a common password and no MFA.
How do you detect password spraying?
Look in the Microsoft Entra sign-in logs for failed sign-ins across many accounts in a short window, often with the same wrong password. Other signs are attempts from countries where you have no staff, attempts against accounts that don’t exist or rarely sign in, and a successful sign-in followed by new inbox rules, forwarding or MFA methods.
Sources: MITRE ATT&CK: Brute Force, Password Spraying (T1110.003); Microsoft Security Blog: Midnight Blizzard, guidance for responders, January 2024; Microsoft Learn: Block legacy authentication with Conditional Access; Microsoft Learn: Security defaults in Microsoft Entra ID; Microsoft Learn: Eliminate bad passwords using Microsoft Entra Password Protection; Microsoft Learn: Configure Microsoft Entra for Zero Trust, protect identities and secrets; Microsoft Learn: Alert classification for password spray attacks; NIST SP 800-63B-4: Digital Identity Guidelines, Authentication, 2025.




