logo

Understanding AitM attacks in Entra ID: Attack mechanics, and defensive measures

ID: 8eac862f-cbe4-5677-ad8b-62f623d78b51

STIX ID: report--8eac862f-cbe4-5677-ad8b-62f623d78b51

Feed Name: Intrinsec Blog

Threat Score
70/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

Author: CERT Intrinsec

...
...

This CERT Intrinsec analysis details how AiTM (Adversary-in-the-Middle) attacks proxy Microsoft Entra ID authentication to capture session tokens and bypass MFA, surveys common delivery vectors and proxy toolkits (e.g., Evilginx, Modlishka, Muraena and commercial phishing-as-a-service), and recommends a layered defense—comprehensive Conditional Access coverage, phishing-resistant MFA (FIDO2/passkeys/CBA), Token Protection, Continuous Access Evaluation and Identity Protection—while noting licensing and operational constraints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.