Windows Entra IDs can be bypassed worryingly easily – here’s what we know

hCciw9cBypDVf32HBmiya 1280 80


  • Experts warn FIDO is not supported on certain clients when accessing Entra ID
  • This triggers a fallback login mechanism that can be picked up
  • Mitigations should be put in place, researchers say

FIDO-based authenticator apps are considered one of the strongest practical defenses against phishing and credential theft, but judging by Proofpoint’s latest research, it is not without its weaknesses.

The company’s researchers say they have found a way to force a target to abandon FIDO-based authentication for a weaker login method which can be picked up in transit.

Share this post:

Leave a Reply

Your email address will not be published. Required fields are marked *

From the latest gadgets to expert reviews and unbeatable deals — dive into our handpicked content across all things tech.