I am the GA of a 10-person startup. Today (March 10, 2026) an GA account was compromised via an AiTM session token theft attack. An attacker used the breached account account to send phishing emails to external contacts.
Our second GA did the following while we scraped Azure activity logs to identify the breach:
- Rest all passwords,
2. Revoked all sign-in sessions via Microsoft Graph API
3. Disabled Security Defaults to enable Conditional Access
4. Created CA policy blocking the identified attacker's IP range
5. Created CA policy to require MFA - but made the CA only grant approved / registered devices by our GA. MFA was already in-place on every user device, however we had not registered / approved specific devices.
6. Created CA policy "Block Legacy Auth" — blocking Exchange ActiveSync and Other clients.
Thus the entire org was booted out of their sessions with no ability to login.
Now every sign-in across the entire tenant is blocked with error 53003. No user can sign in to any Microsoft service — Entra, Azure Portal, Outlook, Teams, Azure CLI, PowerShell, nothing. Users cannot register MFA because they cannot sign in. Complete catch-22.
I've tried
- Signing in via browser, InPrivate, Azure CLI, PowerShell device code flow — all blocked with 53003
- Creating new user accounts via Graph API — also blocked when they try to sign in
- Resetting passwords via Graph API — cannot reset Global Admin passwords
- Registering MFA methods via Graph API — app lacks UserAuthenticationMethod.ReadWrite.All permission
- Re-enabling Security Defaults via Graph API — app lacks Policy.ReadWrite.SecurityDefaults permission
- Modifying CA policies via Graph API — app lacks Policy.ReadWrite.ConditionalAccess permission
- The app cannot grant itself new permissions (lacks AppRoleAssignment.ReadWrite.All)
Have also called multiple Microsoft support numbers but cannot reach a live agent & emailed existing Microsoft support case contacts during normal working hours with no response.
Pls, pls, pls escalate this to Sev A and get me on the phone.
We are mid negotiation of a big contract.