Windows Entra IDs can be bypassed worryingly easily – here’s what we know
- Experts warn FIDO is not supported on certain clients when accessing Entra ID
- This triggers a fallback login mechanism that can be picked up
- Mitigations should be put in place, researchers say
FIDO-based authenticator apps are considered one of the strongest practical defenses against phishing and credential theft, but judging by Proofpoint’s latest research, it is not without its weaknesses.
The company’s researchers say they have found a way to force a target to abandon FIDO-based authentication for a weaker login method which can be picked up in transit.
That way, despite being protected by industry-standard defenses, victims can still end up losing access to key accounts.
Missing security features
The “weakness” in this scenario is that not all browsers support FIDO. Safari on Windows, for example, is not compatible with FIDO-based authentication in Microsoft Entra ID, and when a user with such a setup tries logging in, they are offered an alternative – an SMS-delivered one-time password, email, or an OAuth consent prompt.
All of these can then be picked up via an Adversary-in-the-Middle attack (AitM), relayed to the attackers, and used to log into the account.
“This seemingly insignificant gap in functionality can be leveraged by attackers,” Proofpoint said in its report.
“A threat actor can adjust the AiTM to spoof an unsupported user agent, which is not recognized by a FIDO implementation. Subsequently, the user would be forced to authenticate through a less secure method. This behavior, observed on Microsoft platforms, is a missing security measure.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
So far, Proofpoint says there is no evidence that this method is being abused in the wild, and speculates that threat actors still rather target accounts without multi-factor authentication (MFA) in the first place.
However, as more and more businesses deploy this anti-phishing technique, working around FIDO-based authentication might catch on.
To minimize the risk, businesses should turn off alternative authentication methods for key accounts, or at least turning on additional checks when an alternative is triggered.
Via BleepingComputer
You might also like
Experts warn FIDO is not supported on certain clients when accessing Entra ID This triggers a fallback login mechanism that can be picked up Mitigations should be put in place, researchers say FIDO-based authenticator apps are considered one of the strongest practical defenses against phishing and credential theft, but judging…
Recent Posts
- AI leaders call for tougher protections against AI-aided bioweapons
- 5 Best Smart Speakers (2026): Alexa, Google Assistant, Siri
- I’m an outdoors expert — here are 9 easy-pitch tents I’d recommend for a fuss-free camping trip
- Samsung’s updated Health app unsurprisingly comes with new AI-powered features
- Amazon develops a warehouse robot workers can speak to
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023