Unfixed Microsoft Entra ID Authentication Bypass Threatens Hybrid IDs
ID: 412c213f-76cb-5dc0-971a-84acbb337f7d
STIX ID: report--412c213f-76cb-5dc0-971a-84acbb337f7d
Feed Name: Dark Reading
Cymulate researchers demonstrated a proof-of-concept attack against Microsoft Entra ID Pass-Through Authentication (PTA) agents in which a local administrator on a PTA server injects a DLL that intercepts ValidateCredential calls and forces successful authentication for any synced on-premises AD user across synced domains. The root issue arises when PTA agents mishandle authentication requests across multiple synced domains, allowing an attacker controlling a PTA host to impersonate users (including potentially high-privilege accounts); Microsoft plans code fixes and recommends treating PTA servers as Tier-0, enabling MFA, and implementing domain-aware routing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
