Hunting Conditional Access Policy Bypass in the Wild: Leveraging Malicious Browser Extensions for Seamless Initial Access
ID: a7b58214-6ec7-5700-acac-049604322bb2
STIX ID: report--a7b58214-6ec7-5700-acac-049604322bb2
Feed Name: Mitiga
This report demonstrates a practical Conditional Access Policy bypass that uses the Microsoft Intune Company Portal client_id and a stalled ms-appx-web OAuth redirect to capture authorization codes, redeem access tokens, and access Microsoft Graph from unmanaged, non-compliant devices; it further shows how malicious browser extensions or BiTM attacks can automate token capture. The document includes reproduction steps, example OAuth requests, a detection/hunting query, mitigation recommendations, and notes that Microsoft has since adjusted Graph permissions to address the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
