Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The New United Airlines Policy That Could Get You Kicked Off a Flight

    March 4, 2026

    I tried Tecno’s modular phone concept at MWC – and it quickly got weird

    March 4, 2026

    USB Hubs Can Save You Lots of Hassles—Here Are 5 We Like Best in 2026

    March 4, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»Windows Entra IDs can be bypassed worryingly easily – here’s what we know
    Tech News

    Windows Entra IDs can be bypassed worryingly easily – here’s what we know

    Michael ComaousBy Michael ComaousAugust 14, 20252 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Visual representation of a passkey on a computer chip
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    • Experts warn FIDO is not supported on certain clients when accessing Entra ID
    • This triggers a fallback login mechanism that can be picked up
    • Mitigations should be put in place, researchers say

    FIDO-based authenticator apps are considered one of the strongest practical defenses against phishing and credential theft, but judging by Proofpoint’s latest research, it is not without its weaknesses.

    The company’s researchers say they have found a way to force a target to abandon FIDO-based authentication for a weaker login method which can be picked up in transit.

    That way, despite being protected by industry-standard defenses, victims can still end up losing access to key accounts.


    You may like

    Missing security features

    The “weakness” in this scenario is that not all browsers support FIDO. Safari on Windows, for example, is not compatible with FIDO-based authentication in Microsoft Entra ID, and when a user with such a setup tries logging in, they are offered an alternative – an SMS-delivered one-time password, email, or an OAuth consent prompt.

    All of these can then be picked up via an Adversary-in-the-Middle attack (AitM), relayed to the attackers, and used to log into the account.

    “This seemingly insignificant gap in functionality can be leveraged by attackers,” Proofpoint said in its report.

    “A threat actor can adjust the AiTM to spoof an unsupported user agent, which is not recognized by a FIDO implementation. Subsequently, the user would be forced to authenticate through a less secure method. This behavior, observed on Microsoft platforms, is a missing security measure.”

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    So far, Proofpoint says there is no evidence that this method is being abused in the wild, and speculates that threat actors still rather target accounts without multi-factor authentication (MFA) in the first place.

    However, as more and more businesses deploy this anti-phishing technique, working around FIDO-based authentication might catch on.

    To minimize the risk, businesses should turn off alternative authentication methods for key accounts, or at least turning on additional checks when an alternative is triggered.

    Via BleepingComputer

    You might also like

    bypassed Easily Entra Heres IDs Windows worryingly
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleSenators Press Howard Lutnick’s Former Investment Firm Over Tariff Conflict of Interest Concerns
    Next Article How the Premier League uses AI to boost fan experiences and score new business goals
    Michael Comaous
    • Website

    Michael Comaous is a dedicated professional with a passion for technology, innovation, and creative problem-solving. Over the years, he has built experience across multiple industries, combining strategic thinking with hands-on expertise to deliver meaningful results. Michael is known for his curiosity, attention to detail, and ability to explain complex topics in a clear and approachable way. Whether he’s working on new projects, writing, or collaborating with others, he brings energy and a forward-thinking mindset to everything he does.

    Related Posts

    2 Mins Read

    The New United Airlines Policy That Could Get You Kicked Off a Flight

    4 Mins Read

    I tried Tecno’s modular phone concept at MWC – and it quickly got weird

    3 Mins Read

    USB Hubs Can Save You Lots of Hassles—Here Are 5 We Like Best in 2026

    2 Mins Read

    Google and Epic look to bury the hatchet with new app store settlement

    1 Min Read

    His house burned down. He used the insurance money to build PopSockets.

    1 Min Read

    Google isn’t waiting for a settlement — the 30 percent Android app store fee is dead

    Top Posts

    Discord will require a face scan or ID for full access next month

    February 9, 2026761 Views

    The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

    August 4, 2025564 Views

    Past Wordle answers – all solutions so far, alphabetical and by date

    August 1, 2025230 Views
    Stay In Touch
    • Facebook

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Discord will require a face scan or ID for full access next month

    February 9, 2026761 Views

    The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

    August 4, 2025564 Views

    Past Wordle answers – all solutions so far, alphabetical and by date

    August 1, 2025230 Views
    Our Picks

    The New United Airlines Policy That Could Get You Kicked Off a Flight

    March 4, 2026

    I tried Tecno’s modular phone concept at MWC – and it quickly got weird

    March 4, 2026

    USB Hubs Can Save You Lots of Hassles—Here Are 5 We Like Best in 2026

    March 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 GeekBlog

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.