Vulnerabilities identified by the Modern 42 Labs security research team. We specialise in enterprise IAM and PAM systems, uncovering vulnerabilities within the tools we implement daily.
Intune MAM App Protection Conditional Access Bypass
Vendor: Microsoft·Product: Intune MAM / Entra ID Conditional Access
A self-attested Intune MAM enrolment satisfies the 'require app protection policy' Conditional Access grant, letting the holder of a user's refresh token reach app-protected data without a genuine managed device or app.
Impact
Post-authentication access to the Office 365 mail, files and chat an app protection policy was meant to gate.
Microsoft Entra ID Multi-Factor Authentication Bypass
Vendor: Microsoft·Product: Entra ID Conditional Access
A authentication bypass vulnerability in Microsoft Entra ID that allows attackers to bypass multi-factor authentication mechanisms under specific conditions.
Impact
MFA bypass to allow access to unauthorized access to protected resources
We use cookies and similar technologies to help personalise content, measure the performance of our site, and provide a better experience. By clicking Accept, you consent to the use of all cookies. Learn more.