{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/identity-and-access/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Microsoft Entra ID"],"_cs_severities":["low"],"_cs_tags":["persistence","cloud-security","entra-id","identity-and-access"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThis threat involves the abuse of the Windows Hello for Business (WHfB) credential registration process within Microsoft Entra ID. While WHfB is a standard onboarding and passwordless authentication feature, it can be repurposed by adversaries for persistent access. Attackers who have successfully compromised a valid user account, specifically one with existing WHfB or passkey access, can leverage that access to satisfy multi-factor authentication (MFA) requirements for registering a new, attacker-controlled credential. This credential becomes a permanent fixture of the account, remaining valid even if the user resets their password or if existing browser sessions are revoked. This technique provides a robust mechanism for long-term access that is resistant to standard remediation efforts, necessitating careful monitoring of new credential registration patterns across a tenant.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an adversary to maintain long-term, persistent access to a compromised account within the target's Entra ID environment. Because the registered credential is device-bound and satisfies MFA requirements, the persistence survives common incident response actions such as password resets and session token invalidation. This poses a high risk for continued unauthorized access, data exfiltration, and lateral movement within the cloud identity perimeter.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy detection logic to identify first-seen WHfB credential registrations correlated with new or anomalous source Autonomous System Numbers (ASN) within the tenant environment.\u003c/li\u003e\n\u003cli\u003eReview the sign-in history immediately preceding any detected WHfB registration for signs of deviceless authentication, device-code flow abuse, or anomalous geographic activity.\u003c/li\u003e\n\u003cli\u003eIf unauthorized registration is confirmed, delete the malicious WHfB credential via the Entra portal or Microsoft Graph API, revoke all active sessions, and force a credential re-enrollment from a trusted, physical device.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T18:47:58Z","date_published":"2026-09-10T18:47:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-entra-id-whfb-persistence/","summary":"Adversaries can establish durable, phishing-resistant persistence in Microsoft Entra ID by registering unauthorized Windows Hello for Business (WHfB) credentials to survive password resets and session revocations.","title":"Entra ID Windows Hello for Business Credential Registration Persistence","url":"https://feed.craftedsignal.io/briefs/2026-09-entra-id-whfb-persistence/"}],"language":"en","title":"CraftedSignal Threat Feed - Identity-and-Access","version":"https://jsonfeed.org/version/1.1"}