LIVE · cybersecurity feed
Live wire
security

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... This is that method. Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We&#;x26;#;39;ll u

zeroday.news ·

A recent report highlights a method for identifying user accounts that may have been overlooked during multi-factor authentication (MFA) rollouts. The technique leverages PowerShell scripting in conjunction with Microsoft Graph and Entra ID (formerly Azure Active Directory) to programmatically enumerate accounts and assess their MFA status. This approach is presented as a more efficient alternative to manual inspection of web interfaces, particularly in environments with a large number of user accounts.

The core of the method involves scripting against Microsoft's cloud identity platform. Specifically, it utilizes PowerShell cmdlets to interact with Entra ID and retrieve user account properties. The report notes the use of Microsoft Graph, including beta commands from the Microsoft.Graph.Beta library, to access comprehensive user data. This allows for querying attributes related to MFA configuration, enabling administrators to pinpoint accounts where MFA has not yet been enforced or configured according to policy.

This type of scripting is common for managing large-scale cloud environments. PowerShell provides a robust interface for automating administrative tasks within Microsoft ecosystems, while Microsoft Graph offers a unified API endpoint for accessing data across various Microsoft 365 services. By combining these tools, administrators can develop custom scripts to audit configurations, enforce policies, and generate reports that are not always readily available through standard graphical user interfaces.

The utility of such a script extends beyond initial MFA rollouts. It can be employed for ongoing compliance checks, identifying new accounts or changes to existing accounts that might inadvertently bypass MFA policies. Regular auditing of MFA status is a critical security practice, as even a small number of unprotected accounts can present a significant attack vector for adversaries seeking initial access to an organization's resources.

Mitigation for the underlying issue of missed MFA configurations typically involves a multi-layered approach. This includes robust identity and access management policies, automated provisioning and deprovisioning workflows that enforce MFA from the outset, and continuous monitoring of user authentication methods. Organizations are also advised to regularly review their MFA implementation, conduct penetration testing, and educate users on the importance of MFA.

In a broader context, the report underscores the ongoing challenge of securing cloud environments, particularly as organizations scale their operations. While MFA is a foundational security control, its effective implementation requires diligent management and continuous verification. Tools and techniques that enable administrators to programmatically assess and enforce security configurations are invaluable in maintaining a strong security posture against evolving cyber threats.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise. One log that really bears looking at is the log of successful and failed logins. the call for that is:

phishing

Russian snoops add OAuth abuse to targeted phishing campaigns

Don't click on that State Department meeting invite

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.