An attacker with Global Administrator or Authentication Policy Administrator privileges can register a rogue External Authentication Method (EAM) in Entra. In Varonis’s test tenant, users were able to access their applications without encountering any errors, while the researchers’ server received their passwords, timestamps, and source IP addresses. The attack exploits the fact that a valid token does not necessarily indicate that the user was presented with a genuine Multi-Factor Authentication (MFA) challenge.

This is similar to a previous research by Dirk-Jan Mollema, which demonstrated that a rogue EAM provider could return a signed token to bypass an MFA check. A pixel-perfect replica of Microsoft's sign-in page (Source: Varonis) is recommended for monitoring Authentication Methods Policy changes, particularly unexpected external provider registrations.

A surge in application, service-principal, and permission-grant events could provide additional leads, but attackers can easily modify their tools. After removing the provider and its associated artifacts, security teams should identify everyone who signed in through it, reset their passwords, and review subsequent account activity. Limiting standing access to the administrator roles that can alter authentication policy reduces the likelihood that a compromised privileged account becomes a persistent password trap.

Join 16,000+ SOC teams using ANY.RUN to enhance threat investigations and minimize manual workload.