← All articles

Rogue external MFA provider in Entra captures user passwords during legitimate logins

Varonis Threat Labs detailed a post-compromise technique it calls TrustSink, in which an attacker holding a highly privileged Microsoft Entra account registers a rogue External Authentication Method as an external MFA provider. During normal sign-ins, Entra redirects users to the rogue provider to complete the second factor, and the attacker inserts a convincing Microsoft password prompt that captures the password in plaintext before returning a valid signed token, so the login completes with no error. In testing, every sign-in succeeded while the attacker server logged passwords with source IPs. Resetting a captured password does not remove the rogue provider, which persists in the configuration and works against any external provider model.

Check
Audit Entra External Authentication Methods for unrecognized providers, remove rogue entries, and tighten which roles can register or modify external MFA providers.
Affected
Tenants where an attacker already holds a highly privileged Entra role can have a rogue external MFA provider silently harvest every user's password during normal logins.
Fix
Restrict and monitor privileged Entra roles, alert on External Authentication Method changes, and review provider configuration after any privileged-account compromise.