Microsoft Entra Conditional Access Policies Can Be Bypassed Via Nested App Authentication
ID: 73022e87-711d-5e37-a42a-db919825eec8
STIX ID: report--73022e87-711d-5e37-a42a-db919825eec8
Feed Name: cybersecurityNews.com
NetSPI disclosed a vulnerability where Microsoft’s Nested App Authentication (NAA) SSO flows could broker Azure Portal refresh tokens to certain clients (e.g., ADIbizaUX and Intune portal extensions) to obtain Microsoft Graph access tokens while bypassing Conditional Access Policies; Microsoft classified the issue as medium severity and has fixed the affected flows. An attacker would need to steal an Azure Portal refresh token (valid for 24 hours) to exploit this, and retesting confirms Conditional Access blocking errors are now returned after the fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
