Windows Entra identifiers can be easily bypassed easily – here is what we know


  • Experts warn that Fido is not supported on certain customers when accessing the identifier entered
  • This triggers a rescue connection mechanism that can be picked up
  • Attenuations must be put in place, say the researchers

The applications of authenticators based on Fido are considered one of the strongest practical defenses against phishing and the flight of identification, but to judge by the latest proofpoint research, it is not without its weaknesses.

The company’s researchers say they have found a way to force a target to abandon Fido -based authentication for a lower connection method that can be recovered in transit.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top