Azure AD Conditional Access Bypassed Via Phantom Device Registration and PRT Abuse
ID: 5bf884b7-122a-558a-8c7d-0ae4044c8fcb
STIX ID: report--5bf884b7-122a-558a-8c7d-0ae4044c8fcb
Feed Name: cybersecurityNews.com
Howler Cell (Cyderes) documented a critical attack chain that bypasses Azure AD Conditional Access by abusing unprotected Device Registration Service endpoints and Intune enrollment logic to register phantom devices, mint PRTs with false device claims, and access a production tenant of over 16,000 users without malware or endpoint interaction; the technique mirrors tactics attributed to Storm-2372 and enables directory enumeration and potential tenant takeover via synced on-prem privileged accounts. Recommended mitigations include blocking device-code flows, enforcing TPM attestation and external health validation, scoping Graph API access, and restricting privileged roles to cloud-only PIM-managed accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
