A vulnerability in Microsoft’s popular identity management directory could let an attacker breach multiple employee accounts in an organization by circumventing multi-factor authentication, according to new research from identity security company Okta. The directory in question is Microsoft’s Active Directory Federation Services (ADFS), which allows business partners from different organizations to sign in to shared web applications. A weakness in the multi-factor authentication protocol for ADFS means that a hacker equipped with a user’s password and second “factor,” such as an SMS message, could use that factor in place of any other employee’s in the organization, according to Okta. To breach another user in the organization, the hacker would need access to his or her user name and password on the same ADFS service. “Simply put, if just one employee in a global company wanted to – or if a bad actor compromised the account of one employee – they […]
The post New vuln in Microsoft Active Directory lets attackers bypass multi-factor authentication appeared first on Cyberscoop.
Continue reading New vuln in Microsoft Active Directory lets attackers bypass multi-factor authentication→