An Accenture researcher discovered a vulnerability in Windows Hello for Business (WHfB) that allows downgrade attacks, enabling threat actors to bypass even biometric protections. Using the Evilginx adversary-in-the-middle attack framework, attackers can intercept and alter authentication requests, downgrading WHfB to less secure methods like passwords or OTPs. Microsoft has since released a fix, introducing a new Conditional Access capability called 'authentication strength,' which forces employees to use only phishing-resistant methods for authentication.

5m read timeFrom darkreading.com
Post cover image
Table of contents
Authentication Downgrades With Adversary-in-the-MiddleWHfB's Phishing-Resistant ModelMicrosoft's Remediation: New Conditional Access Policy

Sort: