MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 13 h ago, last 13 h ago, peak #10

Token Protection Flaw Found in Microsoft Entra ID

Original: New on Insinuator: Token Theft in Microsoft Entra ID (Part 3 of 4): Token Protection. It binds refresh tokens to a devic

Security researchers at Insinuator published the third part of their series on token theft in Microsoft Entra ID, examining Token Protection, which binds refresh tokens to a device via the Primary Refresh Token. In testing Microsoft's recommended Teams policy, they found that changing the User-Agent to Linux on the first request yields a usable, non-device-bound token, suggesting the protection can be bypassed.

Why now: A claimed bypass of Microsoft's recommended token protection for Teams is significant for identity security practitioners.

Microsoft Entra IDInsinuatorMicrosoft Teams

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1585081