Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions
ID: 0f83178c-a46a-5e09-b083-8d5050546c9f
STIX ID: report--0f83178c-a46a-5e09-b083-8d5050546c9f
Feed Name: Black Hills Infosec Blog
This blog outlines a red-team social engineering technique that combines Microsoft SSPR with push-based MFA approvals to reset passwords and gain initial Microsoft 365 access without involving the help desk, detailing the pretext, call flow, user coaching, and operational steps, plus ethical RoE considerations, user-psychology levers, Conditional Access outcomes, and defensive guidance (e.g., not approving unsolicited prompts and calling back via known numbers). A case study shows six calls leading to access to Outlook, SharePoint, and Teams and retrieval of sensitive data during an authorized test.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
