Access Management Failures: Teams Impersonation, Infostealer Sessions, and Leaver Risk

Access Management Failures: Teams Impersonation, Infostealer Sessions, and Leaver Risk

•

Episode description

Access Management Failures: Teams Impersonation, Infostealer Sessions, and Leaver Risk

Three separate incidents this week reveal a single, critical vulnerability across UK small businesses: access management. Microsoft Threat Intelligence has confirmed an active campaign exploiting Teams external collaboration to impersonate IT helpdesk staff, tricking employees into installing remote access tools that deploy malicious payloads. Meanwhile, new analysis shows that resetting passwords after infostealer compromise leaves authenticated session tokens active, allowing attackers continued access for days. A separate case study documents a terminated employee retaining elevated access long enough to cause hundreds of thousands in damages, purely because no formal offboarding checklist existed. The technical controls to prevent all three scenarios are available and documented. What is missing is operational discipline: caller verification before granting remote access, session revocation alongside password resets, and comprehensive leaver access audits. This episode provides specific, actionable guidance for small businesses without dedicated security teams, walking through the configuration changes, staff briefings, and process checklists required to close these gaps before they are exploited.

Chapters

  • Introduction Overview of three incidents that all point to access management as the primary UK SMB vulnerability right now, with context from yesterday’s coverage and Microsoft’s new formal confirmation.
  • Attackers Impersonating IT Helpdesk via Microsoft Teams Detailed breakdown of the confirmed Microsoft Teams helpdesk impersonation campaign, including the full technical chain from initial contact to lateral movement, and specific configuration and process changes required to mitigate the risk.
  • Call to Action Brief listener engagement prompt.
  • Infostealer Sessions: The MFA Problem Nobody Is Talking About Analysis of the session token problem in infostealer incidents, why password resets alone are insufficient, and the specific session revocation steps required in Microsoft 365 and other platforms.
  • The Leaver Who Kept Access Case study of a terminated employee retaining elevated access due to absent offboarding processes, with practical guidance on access audits and leaver checklists for small businesses.
  • The Pattern Connecting All Three Synthesis of the common access management gap across all three incidents and the operational discipline required to close it.
  • Closing Practical takeaway and episode close.

Links

No transcript available for this episode.