logo

ADFS - Living in the Legacy of DRS

ID: 3f8d07e2-b57a-54f1-b2fe-de07c7618271

STIX ID: report--3f8d07e2-b57a-54f1-b2fe-de07c7618271

Feed Name: XPN Infosec Blog

Threat Score
75/100

Date Published: 2025-01-12

Date Updated: 2026-07-30

...
...

This blog-post analyzes ADFS OAuth2 internals and Device Registration Services (DRS), demonstrating how device enrollment and device authentication can be abused: an attacker can use the OAuth device code flow to phish users for DRS tokens, programmatically enroll devices (enriching msDS-Device/msDS-KeyCredentialLink), manipulate msDS-Device attributes to impersonate users when ClientTLS is enabled, derive and use Enterprise PRTs to obtain access tokens, and craft forged JWTs if the ADFS signing certificate private key is obtained—highlighting multiple high-impact attack paths against hybrid ADFS/Entra environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.