Linked – In major gaffe, hacked Microsoft test account was assigned admin privileges
As the article below points out, I bet this wasn’t a technical issue. It’s not a bug. It’s a poor configuration choice, yes, likely made worse by a poor change management process. Somewhere along the way, you’d think someone would have it written down that this existed, and someone would see it written down and act on it. That didn’t happen. You’d also like to think there would be a hard rule to enable MFA in any environment, including testing ones.
