Conditional Access misconfigurations allow MFA bypass and Microsoft 365 compromise
Attack Techniques & Methods2026-07-16, 09:12
Conditional Access misconfigurations allow MFA bypass and Microsoft 365 compromise
Huntress researchers demonstrated how two distinct attacks —
Device Code Phishing and ROPC (Resource Owner Password Credentials) — bypass multifactor authentication due to improperly configured Conditional Access policies. In the first campaign, conducted via the Railway platform, attackers obtained legitimate OAuth-токены after victims themselves completed MFA by entering a device code. In the second attack, using the ROPC-флоу, valid credentials were applied to /token, generating new tokens without triggering MFA, which enabled large-scale unauthorized access to Microsoft 365.Both attacks were possible because of narrow Conditional Access scope or policies left in report-only mode (restricted by apps, user groups, or geolocations). As a result, 78 accounts across 64 organizations were compromised.
Vendors
Products