Attackers commonly find themselves in situations in which they must access a resource which is guarded by a multi-factor authentication systems. There are multiple ways that attackers can accomplish this goal. This session will present some ways in which how a red team member, as well as attackers observed by incident responders, have bypassed MFA. The presenter will share techniques used in the field to bypass MFA and demonstrate ways to mitigate, detect, and investigate these same techniques.