The Microsoft Detection and Response Team (DART) recently warned that attackers are increasingly using token theft to circumvent multi-factor authentication (MFA).
“By compromising and replaying a token issued to an identity that has already completed multifactor authentication, the threat actor satisfies the validation of MFA and access is granted to organizational resources accordingly,”
Microsoft Warns of Surge in Token Theft, Bypassing MFA
https://www.esecurityplanet.com/threats/token-theft-bypassing-mfa/