logo

Full Disclosure: A Look at a Recently Patched Microsoft…

ID: 008f0be7-c447-5c99-876f-73c3f3c8d19d

STIX ID: report--008f0be7-c447-5c99-876f-73c3f3c8d19d

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

### Executive Summary: The report documents a Microsoft Graph authentication logging bypass present from roughly June 2023 to March 2024 where changing the oauth2 endpoint to a different tenant ID allowed attackers to enumerate valid UPNs and verify passwords without creating sign-in log entries in the victim tenant; verbose error codes still revealed credential validity. The author provides proof‑of‑concept scripts demonstrating the technique, test evidence showing missing sign-in logs for the alternate-tenant method, and notes Microsoft internally remediated the issue (VULN-107279) and deemed it low severity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.