Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: entra (2 articles)Clear

Rogue external MFA provider in Entra captures user passwords during legitimate logins

Varonis Threat Labs detailed a post-compromise technique it calls TrustSink, in which an attacker holding a highly privileged Microsoft Entra account registers a rogue External Authentication Method as an external MFA provider. During normal sign-ins, Entra redirects users to the rogue provider to complete the second factor, and the attacker inserts a convincing Microsoft password prompt that captures the password in plaintext before returning a valid signed token, so the login completes with no error. In testing, every sign-in succeeded while the attacker server logged passwords with source IPs. Resetting a captured password does not remove the rogue provider, which persists in the configuration and works against any external provider model.

Check
Audit Entra External Authentication Methods for unrecognized providers, remove rogue entries, and tighten which roles can register or modify external MFA providers.
Affected
Tenants where an attacker already holds a highly privileged Entra role can have a rogue external MFA provider silently harvest every user's password during normal logins.
Fix
Restrict and monitor privileged Entra roles, alert on External Authentication Method changes, and review provider configuration after any privileged-account compromise.

Attackers phone Microsoft 365 users to walk them through fake passkey setup

Okta warns of a campaign that phones Microsoft 365 users and talks them through what looks like setting up a passkey, but is actually a phishing kit that hands their account to the attacker. Active since April, the operators register passkey-themed domains and call targets, exploiting unfamiliarity with how passkeys really work. The kit mimics Microsoft's passkey enrollment without registering a real passkey, and pushes the victim to "save a recovery key" that the attacker controls, capturing the access needed to take over the account. The campaign, aimed at extortion, notably targets the passkey adoption process itself, turning a security upgrade into a social-engineering opening.

Check
Tell staff that Microsoft passkey setup happens through a device system prompt, not a phone call or web form, and that anyone calling to walk them through passkey registration is suspicious.
Affected
Microsoft 365 users unfamiliar with passkey enrollment; a convincing phone call plus a look-alike registration page can trick them into handing over the access an attacker needs to take over the account.
Fix
Train users on the genuine passkey enrollment flow, restrict who can register new authentication methods and recovery keys, monitor Entra for unexpected authentication-method changes, and verify unsolicited passkey calls internally.