Request a demo →
← All case studies Education Technology · Incident Response, Entra Remediation, MFA, Team Access & Federation

It Became a Business Problem When the Emails Reached Their Clients

A training and education technology company recovered from business email compromise, removed the attackers’ persistent foothold in Entra and rebuilt access across Microsoft 365, Azure and Google Workspace.

<48 hours from engagement to containment
60 accounts secured with multidimensional MFA
6 months without another account-related incident
THE CHALLENGE

Why a stronger solution was needed

Compromised company accounts were used to send phishing messages to clients. Attackers had established persistence inside Entra that would have survived password resets, administrative accounts faced sustained brute-force pressure, several shared team accounts had MFA disabled because a personal second factor did not fit how the function was used, and client collaboration sometimes depended on personal Google accounts.

RAINBOW SECURE APPROACH

How the engagement was structured

Rainbow Secure contained the active incident, reconstructed the timeline from tenant audit logs, removed attacker persistence from Entra and restored the tenant to a known-good identity configuration. It then secured all 60 Microsoft accounts with rSecureKey MFA, converted 12 shared functions to named Team Access, hardened administrative access, extended governed Entra access to the Azure client environment and federated Google Workspace to the company domain.

WHY RAINBOW SECURE

Why the customer selected this approach

Recovery required both halves of the problem to be solved: remove the foothold already created inside Entra and close the authentication path used to return. Rainbow Secure also made MFA practical for shared functions instead of asking the customer to repeat a control design that employees had already found unworkable.

WHAT WE DID

From problem to governed access

01

Contain and investigate

Stopped the active compromise and reconstructed the timeline from tenant audit logs.

02

Remove Entra persistence

Cleaned the identity objects and configuration that could survive a password reset.

03

Restore tenant trust

Validated the identity environment back to a known-good state.

04

Protect every Microsoft account

Applied rSecureKey MFA across all 60 accounts.

05

Fix shared-function authentication

Converted 12 team accounts to named, individually authenticated access.

06

Harden cloud administration

Governed Entra and Azure administrative access under continuing attack pressure.

07

Federate Google collaboration

Moved shared documents to managed identities on the company domain.

FEATURES IN PRACTICE

What was used, where and why

Rainbow Secure capability Where it was used How it helped
Incident response and forensics Microsoft 365 and the Entra tenant Contained the active compromise in under 48 hours and reconstructed the attack timeline from tenant evidence.
Entra remediation Tenant identity objects and configuration Identified and removed persistent attacker access that password rotation alone would not have eliminated.
rSecureKey multidimensional MFA All 60 Microsoft 365 accounts Added human verification beyond reusable credentials, including accounts that had previously remained exposed.
Team Access 12 shared team functions Replaced one shared login and second-factor problem with named people authenticating individually.
Governed administrative access Entra and Azure administration Hardened the privileged tier against sustained brute-force pressure and made administrative access accountable.
Google Workspace federation Client and partner document collaboration Moved access from personal Google identities to managed accounts on the company’s business domain.
WHAT WAS BEING PROTECTED

The business impact behind the technology

Client relationships

Phishing from a trusted company address can damage confidence beyond the technical incident.

Business email

Compromise creates invoice fraud, impersonation and contract-manipulation risk.

Azure applications serving clients

Identity disruption can affect organizations and learners relying on the platform.

Learner data

Improper access can create contractual and institutional exposure.

Founder and executive authority

A compromised leadership identity can make fraudulent requests appear legitimate.

THREATS REDUCED

Risk connected to control

Threat or weakness Control that addressed it
Business email compromise Incident containment, forensics and complete identity recovery
Persistence surviving password resets Entra object and configuration remediation
Brute force against administrators Governed admin tier and stronger authentication
MFA disabled on shared functions Team Access with individual authentication
Credentials reused or replayed rSecureKey multidimensional MFA across 60 accounts
Personal identities used for collaboration Google Workspace federation to the business domain
BUSINESS OUTCOME

What changed

The active compromise was contained in under 48 hours and attacker persistence was removed from Entra. Sixty accounts received multidimensional MFA, twelve shared functions moved to named Team Access, more than 100 administrative brute-force attempts were blocked each week, and the source case study records six months without another account-related incident.

Verified engagement results from the supplied EdTech BEC Recovery case study. FERPA applies to the education-technology vendor through customer contracts and the school-official relationship where applicable; this story does not claim blanket FERPA compliance.
YOUR ENVIRONMENT WILL BE DIFFERENT

Start with one customer problem and build the right identity-security path.

We can map the users, applications, access risks and evidence requirements involved in your first use case.

Discuss your use case →