Ask your IT director how many identities can sign into your Microsoft 365 tenant. The answer will usually be a headcount — staff, plus a handful of contractors. That number is wrong, and the distance between it and the real one is a fair measure of how much of your business currently has nobody watching it.
"Identity is the perimeter" has been repeated long enough to become wallpaper. It stopped being a prediction years ago and is now a plain description of how intrusions work. What deserves executive attention is not the slogan but the change underneath it: the population of identities inside a mid-market company has changed composition, while most of the controls those companies bought were designed for the old population.
MFA proves a moment, then issues a bearer token
Multi-factor authentication is the control most organizations consider finished. Purchased, deployed, argued about, moved to the done column.
Consider the mechanism. MFA proves something at a single instant: sign-in. What the system issues afterward is a session token — a bearer credential meaning, in effect, that this browser has already been vouched for. Whatever holds that token is treated as the user, with no password required and no second factor asked for again.
That gap is where modern credential theft operates. This is analysis rather than a warning about a specific campaign: a proxy sign-in page positioned between an employee and the real service can pass the password and the one-time code through in real time and keep the resulting session for itself. The employee sees a successful login and gets on with the day. Meanwhile an attacker holds a valid, fully authenticated session that a password reset does not, on its own, revoke.
So "we have MFA" describes a purchase, not a posture. Narrowing the gap takes phishing-resistant authentication — passkeys and hardware-bound credentials cryptographically tied to the real domain, which cannot be relayed to a counterfeit one — paired with Conditional Access policies that evaluate device health, location and risk continuously rather than once at the door. Those are separate projects with separate budgets. Plenty of companies believe they bought the second when they bought the first.
The identities nobody onboarded
Payroll stopped describing your identity list some time ago.
Every integration creates a principal. A finance platform wired into the accounting system holds credentials. The scheduling tool that reads calendars holds a consent grant. Somewhere, a script written four years ago by an employee who has since left runs under a service account whose password never expires. API keys sit in repositories. None of it appears in a headcount, and none of it goes through offboarding, because nobody experienced its creation as a hire.
AI agents are the newest arrivals in this population and the most consequential. An agent holds a credential and a permission scope and acts on behalf of a person, frequently across mail, files and chat at once. Treat it as an account, because that is what it is. When an employee grants a third-party assistant access to a mailbox to try it out, the consent usually outlives the trial, the enthusiasm, and sometimes the employee. That grant is not a password. Resetting a password does nothing to it, a login report that counts humans will not surface it, and within its scope it can read everything.
Translate that into operator terms. A route for data to leave your tenant can now exist with no breach, no malware and no stolen credential — only a consent click nobody reviewed. Shadow AI is less a productivity governance problem than an authorization problem wearing a friendly interface.
Your recovery path is an authentication factor
Most security roadmaps skip the next part, and it is the part experienced practitioners actually worry about.
Every strong authentication system needs a way to recover. Phones break. Tokens get left in a desk drawer in Culver City while the executive is in a hotel in Chicago. Someone has to be able to restore access, which means someone has to be able to bypass the control you spent a year deploying.
Usually that someone is a person answering a phone. Traditional verification — recognizing the caller, asking for a birth date, confirming a manager's name — was designed for a period when imitating a particular executive's voice took effort and equipment. Synthetic voice is now ordinary consumer technology, so treating familiarity as evidence is a habit that has outlived its basis. An urgent, plausible, slightly stressed call from a voice that sounds like your CFO should be handled as an unauthenticated request, because that is what it is.
The correction is organizational rather than technical, and thoroughly unglamorous. Identity recovery deserves a written standard: verification through an independent channel, callback to a number of record rather than the number that called in, a named second approver for privileged accounts, and a firm rule that no authentication factor is reset on the strength of a voice. It also depends on whoever staffs your help desk knowing your organization well enough to notice that a request is strange, which is an argument about staffing models rather than software. Whoever handles an identity reset is functionally part of your security architecture. Few companies have ever described that role in those terms.
What a Los Angeles operator can decide this quarter
The useful move is not a product purchase. It is assigning ownership to something that currently has none.
- Name an owner for identity. One accountable person, internal or through your managed IT services partner, whose job includes knowing what can authenticate.
- Inventory the non-human population. Service accounts, app registrations, consent grants, API keys, agents. Each one gets a business owner, a scope and an expiry.
- Close user-granted consent to company data. Route approval to a human who understands what is being requested.
- Make phishing-resistant sign-in the default for administrators, finance and executives first. Broad rollout can follow.
- Rehearse the reset. Have someone attempt a social-engineered factor reset against your own process, then watch what your people do.
A prediction, labelled as one: the identity question on insurance applications and acquisition diligence will stop being whether you have MFA. It will become whether you can produce a list of every non-human identity with access to your data and name who approved each one.
The question for your next leadership meeting
Perimeter thinking was always about knowing what sits inside and what sits outside. That boundary no longer follows your network. It runs through a list of things permitted to act as your company: people you hired, integrations you approved, agents you may not know exist, and whoever can convincingly ask for a reset on a Tuesday afternoon.
The board-level question is no longer whether you have multi-factor authentication. Ask instead who and what can act as us, who approved each of them, and how quickly someone could talk their way onto that list.
Pro Link Systems has supported Los Angeles businesses from Woodland Hills since 1999, and answers the phone live with an in-house, US-based team, twenty-four hours a day. For a clear-eyed review of who and what can authenticate into your environment, start with our cybersecurity practice at prolinksystems.com/cybersecurity-services.
Ready to talk to a real IT engineer?
Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.