Azure AD Security Bypass Exploits Phantom Device Registration and PRT Abuse
ID: aacdcb54-b62e-504d-9c42-dcfa6b80a4cf
STIX ID: report--aacdcb54-b62e-504d-9c42-dcfa6b80a4cf
Feed Name: Cyber Press
Threat Score
### Executive summary: This report describes a red-team discovery that phantom device registration at the Device Registration Service (DRS) and Primary Refresh Token (PRT) abuse can fully bypass Microsoft Entra ID (Azure AD) Conditional Access and Intune compliance checks, enabling tenant takeover (including Global Administrator accounts) without touching corporate endpoints; researchers reproduced the chain in a production tenant and linked similar activity to the Storm-2372 APT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
