Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Entra CAPs Bypass via Nested App Authentication

Microsoft Entra CAPs Bypass via Nested App Authentication

Posted on June 22, 2026 By CWS

Microsoft’s Entra Conditional Access Policies (CAPs), critical for securing Azure and Microsoft 365 environments, were recently exposed to a bypass vulnerability through Nested App Authentication (NAA). This revelation was made by security research firm NetSPI.

Understanding the Vulnerability

CAPs serve as an essential line of defense by enforcing multi-factor authentication, device compliance, and location-based restrictions, especially when user credentials are at risk. However, NetSPI’s findings demonstrate that attackers could potentially access Microsoft Graph tokens without triggering Conditional Access checks.

The exploit takes advantage of Microsoft’s customized OAuth protocol for Single Sign-On (SSO). Specifically, it involves how refresh tokens are managed and exchanged among first-party applications. This discovery builds on existing research related to Family of Client IDs (FOCI) and NAA, also known as BroCI, which has been documented by experts from Secureworks, SpecterOps, among others.

Mechanics of the Bypass

Nested App Authentication, a component of Microsoft’s SSO, allows host applications like the Azure Portal to facilitate authentication for nested applications. This means users don’t need to reauthenticate when switching services, as the host app can silently exchange its cached refresh token for a new access token.

One critical aspect involves specific redirect URIs and parameters such as brk_client_id and brk_redirect_uri in OAuth requests, which enable token sharing across applications without user involvement. The vulnerability was identified when this NAA mechanism was used with ADIbizaUX, a key part of the Azure Portal, which holds extensive Microsoft Graph permissions.

Impact and Resolution

NetSPI discovered that an Azure Portal refresh token, when brokered to ADIbizaUX for a Microsoft Graph token, bypassed Conditional Access evaluations. Notably, operations using FOCI-enabled clients like Microsoft Teams were correctly blocked. This points to a specific issue with the NAA-based flow.

Further analysis revealed two additional Microsoft Intune portal applications capable of acquiring Microsoft Graph tokens via NAA without Conditional Access enforcement. An attacker could exploit this by capturing an Azure Portal refresh token, potentially through phishing or adversary-in-the-middle attacks.

The vulnerability’s impact was mitigated by the token’s non-renewable 24-hour validity, but it still offered a substantial window for exploitation. After being reported to Microsoft Security Response Center, the issue was classified as medium severity. Microsoft has since issued a fix, ensuring that NAA flows now correctly enforce Conditional Access policies.

This incident highlights the risks associated with deviations from standard OAuth practices, which, although aimed at enhancing SSO usability, can inadvertently introduce significant security vulnerabilities.

Cyber Security News Tags:Azure, Conditional Access, Cybersecurity, Microsoft 365, Microsoft Entra, NetSPI, OAuth, Security, Single Sign-On, Vulnerability

Post navigation

Previous Post: Critical Dify Vulnerabilities Could Expose AI Data
Next Post: ShapedPlugin WordPress Plugins Hit by Supply Chain Attack

Related Posts

BK Technologies Data Breach – Hackers Compromise IT Systems and Exfiltrate Data BK Technologies Data Breach – Hackers Compromise IT Systems and Exfiltrate Data Cyber Security News
Python-powered Toolkit for Information Gathering and reconnaissance Python-powered Toolkit for Information Gathering and reconnaissance Cyber Security News
Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement Cyber Security News
Kimwolf Botnet Hacked 2 Million Devices and Turned User’s Internet Connection as Proxy Node Kimwolf Botnet Hacked 2 Million Devices and Turned User’s Internet Connection as Proxy Node Cyber Security News
NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks Cyber Security News
Hackers Attacking Palo Alto Networks’ GlobalProtect VPN Portals with 2.3 Million Attacks Hackers Attacking Palo Alto Networks’ GlobalProtect VPN Portals with 2.3 Million Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ClawHub Plugins Exploit Organizational Scopes in AI Ecosystem
  • Apple Resolves Security Flaw in Beats Studio Buds
  • Weekly Cyber Threat Summary: Major Incidents Unveiled
  • LLM API Credentials Leak in AI iOS Apps: A Growing Concern
  • ShapedPlugin WordPress Plugins Hit by Supply Chain Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ClawHub Plugins Exploit Organizational Scopes in AI Ecosystem
  • Apple Resolves Security Flaw in Beats Studio Buds
  • Weekly Cyber Threat Summary: Major Incidents Unveiled
  • LLM API Credentials Leak in AI iOS Apps: A Growing Concern
  • ShapedPlugin WordPress Plugins Hit by Supply Chain Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark