logo

TokenSmith – Bypassing Intune Compliant Device Conditional Access

ID: 8622408d-42fb-5a6c-9e0c-d56420bc08c0

STIX ID: report--8622408d-42fb-5a6c-9e0c-d56420bc08c0

Feed Name: JUMPSEC Labs

Threat Score
75/100

Date Published: 2024-12-20

Date Updated: 2026-04-28

Author: Sunny Chau

...
...

**Entra ID / Intune Conditional Access bypass:** A proof-of-concept demonstrates that the Intune Company Portal's first-party client can be abused to return an authorization code via an ms-appx-web:// redirect URI, allowing attackers who can authenticate (or hijack session cookies) to exchange the code for access/refresh tokens usable against Microsoft Graph and AD Graph. The author documents the discovery, provides exploit steps and a tool (TokenSmith) that automates token retrieval, and recommends enforcing MFA for the Company Portal and monitoring sign-in logs for the client ID `9ba1a5c7-f17a-4de9-a1f1-6178c8d51223`.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.