logo

Bypassing Two-Factor Authentication on OWA & Office365 Portals

ID: 65b5ae40-d157-588d-beeb-9580d010602f

STIX ID: report--65b5ae40-d157-588d-beeb-9580d010602f

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2016-11-02

Date Updated: 2026-04-27

Author: BHIS

...
...

Black Hills Information Security published a technical advisory and PoC showing that Exchange Web Services (EWS) can be used to bypass Outlook Web Access and Office365 multi-factor authentication protections: using the MailSniper tool and valid credentials, an attacker can query the EWS endpoint (Exchange.asmx) to read/search a victim’s mailbox even when OWA is protected by DUO or Azure MFA; the post includes test results, screenshots, mitigation suggestions (restrict EWS, require VPN, or lock down EWS per-user), and a disclosure timeline with Microsoft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.