Skip to content
Threat Feed

Product

Microsoft Entra ID

6 briefs RSS
medium advisory

Microsoft Entra ID Guest Account Promoted to Member

A sophisticated threat actor, having compromised an existing guest account in Microsoft Entra ID, can establish persistent access and elevate privileges by performing a Guest-to-Member account conversion, which grants full directory read access and bypasses Conditional Access restrictions, enabling stealthy long-term access and reconnaissance.

Microsoft Entra ID cloud identity persistence azure microsoft-entra-id
1r 1t
high advisory

Microsoft Entra ID Temporary Access Pass (TAP) Abuse for MFA Bypass and Persistence

An attacker with elevated privileges abuses the Microsoft Entra ID Temporary Access Pass (TAP) feature to bypass multi-factor authentication (MFA), gain unauthorized access to target user accounts, and establish persistence by registering new authentication methods.

Microsoft Entra ID cloud identity azure entra-id mfa-bypass persistence lateral-movement initial-access
3r 2t
high advisory

Microsoft 365 OAuth Device Code Phishing Exploits Non-Compliant Devices

Attackers are actively exploiting the OAuth device code flow in Microsoft 365 to bypass multi-factor authentication (MFA) and gain initial access, leveraging phishing kits like Kali365 and tradecraft similar to Storm-2372 to harvest MFA-satisfied tokens from non-compliant or attacker-controlled devices, and subsequently establishing persistence through device registration.

Microsoft 365 +4 cloud saas identity microsoft-365 initial-access phishing persistence
2r 3t
high advisory

Entra ID Microsoft Authentication Broker DRS Sign-In from Suspicious ASN

Detects Microsoft Entra ID sign-in activity where the Microsoft Authentication Broker requests the Device Registration Service from a suspicious ASN, indicating potential OAuth phishing or adversary-in-the-middle device registration.

Microsoft Entra ID cloud identity azure entra_id sign-in_logs threat_detection initial_access persistence +1
2r 3t
high threat

Storm-2949 Abuses SSPR for Cloud-Wide Data Exfiltration

Storm-2949 compromised cloud identities through social engineering and abused the Self-Service Password Reset (SSPR) process to bypass MFA and gain persistent access, enabling lateral movement and data exfiltration from Microsoft 365 and Azure environments.

Microsoft Entra ID +3 Storm-2949 cloud-security credential-access data-exfiltration social-engineering
2r 6t
medium advisory

Tycoon2FA AiTM Phishing via Microsoft Entra ID Sign-Ins

Detects Microsoft Entra ID sign-ins consistent with Tycoon2FA phishing-as-a-service (PhaaS) adversary-in-the-middle (AiTM) activity targeting Microsoft 365 and Gmail, where the Microsoft Authentication Broker requests tokens for Microsoft Graph or Exchange Online, or the Office web client application authenticates to itself, combined with Node.js-style user agents (node, axios, undici).

Microsoft Entra ID +3 tycoon2fa aitm entra_id phishing credential_access
2r 2t