Skip to content
Threat Feed
low advisory

Entra ID Windows Hello for Business Credential Registration Persistence

Adversaries can establish durable, phishing-resistant persistence in Microsoft Entra ID by registering unauthorized Windows Hello for Business (WHfB) credentials to survive password resets and session revocations.

This threat involves the abuse of the Windows Hello for Business (WHfB) credential registration process within Microsoft Entra ID. While WHfB is a standard onboarding and passwordless authentication feature, it can be repurposed by adversaries for persistent access. Attackers who have successfully compromised a valid user account, specifically one with existing WHfB or passkey access, can leverage that access to satisfy multi-factor authentication (MFA) requirements for registering a new, attacker-controlled credential. This credential becomes a permanent fixture of the account, remaining valid even if the user resets their password or if existing browser sessions are revoked. This technique provides a robust mechanism for long-term access that is resistant to standard remediation efforts, necessitating careful monitoring of new credential registration patterns across a tenant.

Impact

Successful exploitation allows an adversary to maintain long-term, persistent access to a compromised account within the target's Entra ID environment. Because the registered credential is device-bound and satisfies MFA requirements, the persistence survives common incident response actions such as password resets and session token invalidation. This poses a high risk for continued unauthorized access, data exfiltration, and lateral movement within the cloud identity perimeter.

Recommendation

  • Deploy detection logic to identify first-seen WHfB credential registrations correlated with new or anomalous source Autonomous System Numbers (ASN) within the tenant environment.
  • Review the sign-in history immediately preceding any detected WHfB registration for signs of deviceless authentication, device-code flow abuse, or anomalous geographic activity.
  • If unauthorized registration is confirmed, delete the malicious WHfB credential via the Entra portal or Microsoft Graph API, revoke all active sessions, and force a credential re-enrollment from a trusted, physical device.

Immediate actions

Implement monitoring for 'Add Windows Hello for Business credential' operations in Azure Audit Logs

Detection Engineering 72h

Threat Hunt

Identify WHfB registrations from ASNs not previously associated with a user in the last 14 days

T1098.001 medium medium confidence convert to detection

Data: Azure Audit Logs