How to Find MFA Bypasses in Conditional Access Policies

Описание к видео How to Find MFA Bypasses in Conditional Access Policies

Conditional access policies allow organizations to create fine-grained controls over how MFA is applied during authentication to Microsoft services such as Microsoft 365 and Azure. Occasionally, configurations are made that enable single factor access in certain scenarios. As an external attacker who compromises a credential it may be possible to discover these MFA inconsistencies. As an organization managing conditional access policies each one should be checked regularly to ensure loopholes aren't being unintentionally created. This video demonstrates tools that can be used to find potential single factor access conditions in conditional access policies.

Links:
What are Conditional Access Policies? https://learn.microsoft.com/en-us/azu...
MFASweep: https://github.com/dafthack/MFASweep
ROADTools: https://github.com/dirkjanm/ROADtools

Breaching the Cloud Training: https://www.antisyphontraining.com/br...

Комментарии

Информация по комментариям в разработке