Conditional Access misconfigurations allow MFA bypass and Microsoft 365 compromise

Conditional Access misconfigurations allow MFA bypass and Microsoft 365 compromise
Huntress researchers demonstrated how two distinct attacks — Device Code Phishing and ROPC (Resource Owner Password Credentials) — bypass multifactor authentication due to improperly configured Conditional Access policies. In the first campaign, conducted via the Railway platform, attackers obtained legitimate OAuth-токены after victims themselves completed MFA by entering a device code. In the second attack, using the ROPC-флоу, valid credentials were applied to /token, generating new tokens without triggering MFA, which enabled large-scale unauthorized access to Microsoft 365.
Both attacks were possible because of narrow Conditional Access scope or policies left in report-only mode (restricted by apps, user groups, or geolocations). As a result, 78 accounts across 64 organizations were compromised.
Vendors
Huntress
Microsoft
Railway
Products
Conditional Access
Mfa
Microsoft 365
Oauth
Ropc