security1 publisher
A rogue Entra MFA provider captures plaintext passwords inside a sign-in that still succeeds
Varonis Threat Labs registered its own External Authentication Method in a test Entra tenant and served a copy of Microsoft's password prompt during the second factor. Every sign-in completed, and the passwords landed in a file.
Publishers:varonis.com
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives75
- Confidence55