February 17, 2026 Attackers bypass MFA with token theft, AiTM phishing, and push fatigue. This guide shows how to add Microsoft Entra Conditional Access policies, test in report-only, and roll out safely with device, session, and admin protections.