Fake OAuth client IDs are helping attackers slip past sign

Cybersecurity researchers have identified a new technique where attackers spoof OAuth client IDs to bypass sign-in logs in Microsoft Entra ID. This method allows malicious actors to perform account enumeration and password spraying while remaining undetected by standard telemetry.
Why it matters
This vulnerability poses a significant risk to enterprise cloud security, as it allows attackers to probe for valid credentials without triggering traditional security alerts.
Fake OAuth client IDs are helping attackers slip past sign-in logs Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, the globally unique identifier assigned to an application and passed as client_id in an authentication request. Microsoft Entra ID records that value as the application ID in its sign-in logs, and the way it handles unfamiliar identifiers opens a gap that operators have started to work through.
The article is a technical report on cybersecurity threats and research findings.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in