logo

Legacy Protocol Flaws in Microsoft Entra ID Let Hackers Bypass MFA and Conditional Access

ID: c195a273-6b76-56ec-9ebf-451b6926d0a0

STIX ID: report--c195a273-6b76-56ec-9ebf-451b6926d0a0

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-05-12

Date Updated: 2026-04-19

Author: Mandvi

...
...

Executive summary: Guardz Research uncovered a large, automated campaign abusing legacy authentication protocols (BAV2ROPC, SMTP AUTH, POP3, IMAP4) in Microsoft Entra ID to silently obtain access tokens that bypass MFA and Conditional Access; attackers performed credential spraying and brute-force attacks from hundreds of IPs targeting Exchange Online and privileged admin accounts, with thousands of login attempts observed, and the report recommends disabling legacy auth and migrating to modern authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.