👩💻 Abusing FIDO2 passkeys to take over Global Administrators in Entra ID
Microsoft has recently published a Graph API that allows administrators to pre-provision passkeys for users. From an offensive security point of view this raises the question whether this functionality can be abused to take over accounts.
https://www.secura.com/services/information-technology/vapt/what-can-be-pentested/cloud-pentesting/abusing-fido2-passkeys
#azure
Post #1031
488

- 👍 2
- ❤ 1
- 🔥 1