A security vulnerability in Microsoft Entra ID’s legacy login protocols was exploited by attackers to bypass Multi-Factor Authentication, mainly targeting admin accounts across various sectors. This highlights the risks associated with outdated authentication methods in cloud environments. (Affected: {Organizations using legacy authentication protocols in Microsoft Entra ID})
Keypoints :
- Cybersecurity firm Guardz uncovered a campaign exploiting a flaw in Microsoft Entra ID’s legacy authentication, allowing attackers to bypass MFA.
- The attack used Basic Authentication Version 2 – Resource Owner Password Credential (BAV2ROPC), a deprecated login method that circumvents modern security features.
- Target sectors included financial services, healthcare, manufacturing, and technology, with a focus on administrator accounts.
- The campaign consisted of an initial low-intensity phase followed by a surge in brute-force and credential spraying attacks from March 18 to April 7, 2025.
- Over 9,000 suspicious login attempts were detected, primarily from Eastern Europe and Asia-Pacific regions, with a significant focus on Exchange Online and Microsoft Authentication Library endpoints.
- Guardz warns that many organizations still rely on vulnerable legacy protocols such as SMTP AUTH and IMAP4, which bypass MFA and conditional access.
- Experts recommend immediate disabling of legacy authentication, enforcing modern MFA-enabled login methods, and enhanced monitoring to prevent exploitation.
Read More: https://hackread.com/legacy-login-microsoft-entra-id-breach-cloud-accounts/