Mmastodon TechnologyCybersecurity first seen 13 h ago, last 13 h ago, peak #10
Token Protection Flaw Found in Microsoft Entra ID
Original: New on Insinuator: Token Theft in Microsoft Entra ID (Part 3 of 4): Token Protection. It binds refresh tokens to a devic
Security researchers at Insinuator published the third part of their series on token theft in Microsoft Entra ID, examining Token Protection, which binds refresh tokens to a device via the Primary Refresh Token. In testing Microsoft's recommended Teams policy, they found that changing the User-Agent to Linux on the first request yields a usable, non-device-bound token, suggesting the protection can be bypassed.
Why now: A claimed bypass of Microsoft's recommended token protection for Teams is significant for identity security practitioners.
Microsoft Entra IDInsinuatorMicrosoft Teams
Evidence
- New on Insinuator: Token Theft in Microsoft Entra ID (Part 3 of 4): Token Protection. It binds refresh tokens to a device via the PRT. We tested Microsoft's recommended Teams policy: change the User-Agent to Linux on the first request and you get a usable, non-device-bound… · Insinuator@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1585081