An 81-million-attempt campaign succeeding through a legacy authentication flow is a hard reminder that identity security is only as strong as its least-tested policy. MFA that isn’t enforced everywhere isn’t really MFA it’s a false sense of coverage. Closing gaps like ROPC, auditing Conditional Access scope, and treating identity as a continuously monitored system rather than a one-time deployment is what separates organizations that read about campaigns like this from organizations that end up in the incident report.