Legacy Login in Microsoft Entra ID Exploited to Breach Cloud Accounts

Legacy Login in Microsoft Entra ID Exploited to Breach Cloud Accounts

A security vulnerability in Microsoft Entra ID’s legacy login protocols was exploited by attackers to bypass Multi-Factor Authentication, mainly targeting admin accounts across various sectors. This highlights the risks associated with outdated authentication methods in cloud environments. (Affected: {Organizations using legacy authentication protocols in Microsoft Entra ID})

Keypoints :

  • Cybersecurity firm Guardz uncovered a campaign exploiting a flaw in Microsoft Entra ID’s legacy authentication, allowing attackers to bypass MFA.
  • The attack used Basic Authentication Version 2 – Resource Owner Password Credential (BAV2ROPC), a deprecated login method that circumvents modern security features.
  • Target sectors included financial services, healthcare, manufacturing, and technology, with a focus on administrator accounts.
  • The campaign consisted of an initial low-intensity phase followed by a surge in brute-force and credential spraying attacks from March 18 to April 7, 2025.
  • Over 9,000 suspicious login attempts were detected, primarily from Eastern Europe and Asia-Pacific regions, with a significant focus on Exchange Online and Microsoft Authentication Library endpoints.
  • Guardz warns that many organizations still rely on vulnerable legacy protocols such as SMTP AUTH and IMAP4, which bypass MFA and conditional access.
  • Experts recommend immediate disabling of legacy authentication, enforcing modern MFA-enabled login methods, and enhanced monitoring to prevent exploitation.

Read More: https://hackread.com/legacy-login-microsoft-entra-id-breach-cloud-accounts/