ADFS - Living in the Legacy of DRS
ID: 3f8d07e2-b57a-54f1-b2fe-de07c7618271
STIX ID: report--3f8d07e2-b57a-54f1-b2fe-de07c7618271
Feed Name: XPN Infosec Blog
This blog-post analyzes ADFS OAuth2 internals and Device Registration Services (DRS), demonstrating how device enrollment and device authentication can be abused: an attacker can use the OAuth device code flow to phish users for DRS tokens, programmatically enroll devices (enriching msDS-Device/msDS-KeyCredentialLink), manipulate msDS-Device attributes to impersonate users when ClientTLS is enabled, derive and use Enterprise PRTs to obtain access tokens, and craft forged JWTs if the ADFS signing certificate private key is obtained—highlighting multiple high-impact attack paths against hybrid ADFS/Entra environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
