logo

Bypassing MFA on Microsoft Azure Entra ID

ID: 00ac3e93-e031-5e51-9668-faae01df28d5

STIX ID: report--00ac3e93-e031-5e51-9668-faae01df28d5

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-05-01

Date Updated: 2026-03-24

Author: Jack Barradell-Johns

...
...

A red team demonstrates compromising an Azure Entra ID tenant by chaining Azure Seamless SSO Kerberos ticket injection with a Conditional Access misconfiguration that bypassed MFA via a Linux user-agent, then meeting domain-joined SSO requirements using a portable Firefox and negotiate authentication to access the Azure portal without the user’s password or MFA. The report highlights common misconfigurations (overly broad Linux exclusions, policy typos/disabled rules, default MachineAccountQuota) and recommends enforcing MFA universally, setting MAQ to 0, restricting unmanaged application execution (e.g., AppLocker), and detecting suspicious logins such as mismatched device-to-user patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.