TokenSmith – Bypassing Intune Compliant Device Conditional Access
ID: 8622408d-42fb-5a6c-9e0c-d56420bc08c0
STIX ID: report--8622408d-42fb-5a6c-9e0c-d56420bc08c0
Feed Name: JUMPSEC Labs
**Entra ID / Intune Conditional Access bypass:** A proof-of-concept demonstrates that the Intune Company Portal's first-party client can be abused to return an authorization code via an ms-appx-web:// redirect URI, allowing attackers who can authenticate (or hijack session cookies) to exchange the code for access/refresh tokens usable against Microsoft Graph and AD Graph. The author documents the discovery, provides exploit steps and a tool (TokenSmith) that automates token retrieval, and recommends enforcing MFA for the Company Portal and monitoring sign-in logs for the client ID `9ba1a5c7-f17a-4de9-a1f1-6178c8d51223`.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
