An attacker with Global Administrator or Authentication Policy Administrator privileges can register a rogue External Authentication Method (EAM) in Entra. Entra then treats the attacker-controlled service as an MFA provider for users assigned to it. The provider needs an application registration, a service principal and a publicly reachable HTTPS... Weiterlesen
Intelligence View
Researchers Found an MFA Attack That Steals Passwords While Letting Users Log In Normally
An attacker with Global Administrator or Authentication Policy Administrator privileges can register a rogue External Authentication Method (EAM) in Entra. Entra then treats the attacker-controlled service as an MFA provider for users…
SOCIAL SHARE CARD GENERATOR