Windows Entra IDs can be bypassed worryingly easily – here’s what we know




  • Experts warn FIDO is not supported on certain clients when accessing Entra ID
  • This triggers a fallback login mechanism that can be picked up
  • Mitigations should be put in place, researchers say

FIDO-based authenticator apps are considered one of the strongest practical defenses against phishing and credential theft, but judging by Proofpoint’s latest research, it is not without its weaknesses.

The company’s researchers say they have found a way to force a target to abandon FIDO-based authentication for a weaker login method which can be picked up in transit.

https://cdn.mos.cms.futurecdn.net/hCciw9cBypDVf32HBmiya.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img