logo

Hunting Conditional Access Policy Bypass in the Wild: Leveraging Malicious Browser Extensions for Seamless Initial Access

ID: a7b58214-6ec7-5700-acac-049604322bb2

STIX ID: report--a7b58214-6ec7-5700-acac-049604322bb2

Feed Name: Mitiga

Threat Score
70/100

Date Published: 2026-07-16

Date Updated: 2026-07-29

...
...

This report demonstrates a practical Conditional Access Policy bypass that uses the Microsoft Intune Company Portal client_id and a stalled ms-appx-web OAuth redirect to capture authorization codes, redeem access tokens, and access Microsoft Graph from unmanaged, non-compliant devices; it further shows how malicious browser extensions or BiTM attacks can automate token capture. The document includes reproduction steps, example OAuth requests, a detection/hunting query, mitigation recommendations, and notes that Microsoft has since adjusted Graph permissions to address the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.