Most Important Detection – Vishing/Rogue MFA Takeover/Helpdesk-Support Impersonation 2026: Teams External IT-Support Impersonation Followed by Credential/MFA Change

Detects potential vishing or account takeover precursor activity where an external or guest Microsoft Teams user, impersonating IT or Help Desk support, communicates with a user who subsequently modifies their credentials or MFA configuration within the same 24-hour period.