How to Find MFA Bypasses in Conditional Access Policies

แชร์
ฝัง
  • เผยแพร่เมื่อ 2 ม.ค. 2025

ความคิดเห็น • 36

  • @meazer
    @meazer 2 ปีที่แล้ว +5

    great video. very well-condensed and no needless tangents. so many other people would've made this video 30 mins long. this is perfect, keep it up.

  • @owensben
    @owensben 2 ปีที่แล้ว +2

    Very well presented and straight to points with demos, nice work!
    Shows the importance of a policy which blocks access all operating systems but allows connections from operating systems which you supported, such as iOS, Android, Windows and MacOS. Like the tools you showed and thanks for sharing.
    Subscribed.

  • @ajmaddox1540
    @ajmaddox1540 2 ปีที่แล้ว +1

    Beau - the account that was 'compromised' for your example and that you utilized to do your MFA sweep -- was it elevated at all? any admin permission roles?

    • @pelicansurfs
      @pelicansurfs 2 ปีที่แล้ว

      Curious about this as well

  • @MrJoeyverlinden
    @MrJoeyverlinden 2 ปีที่แล้ว +2

    Can't find the device emulation mode in my (fully patched) Edge browser. How did you open it? 🤔

  • @jmesweeney
    @jmesweeney 2 ปีที่แล้ว +5

    Very informative video. I'm 100% going to be replicating this / testing a couple of scenarios myself. Thank you for sharing this knowledge 👍 Keep up the good work!

  • @michaelwaterman3553
    @michaelwaterman3553 2 ปีที่แล้ว +2

    Wow, this is great info! Going to share with my team on Monday. Big thanks!

  • @hullan666
    @hullan666 9 หลายเดือนก่อน

    Hi! I have built some CA policies that I'm pretty sure are watertight but just wanted to check with this script. However, I get a "Login appears to have failed" on almost all the logins? The Graph API and the Azure mgmt API are the two only ones that give me the green text with "the response indicates MFA is in use"

  • @PaulLinger
    @PaulLinger 2 ปีที่แล้ว +2

    This is a great video. Appreciate you creating the tool, will def be leveraging tomorrow morning lol.

  • @melonscratcher
    @melonscratcher 2 ปีที่แล้ว +1

    Hey Beau - Great video! First time I watched your content and I do like it a lot! Skills to pay the bills, keep it rolling. SUBSCRIBED !!!

  • @Zachsnotboard
    @Zachsnotboard 10 หลายเดือนก่อน

    so if you were to use -UsersPermissionToReadOtherUsersEnabled FALSE , would this keep tools like MFA sweep from getting this info ?

  • @BVey-tt6wl
    @BVey-tt6wl ปีที่แล้ว

    What privileges did the (breached) account hold?

  • @iamshubhamswaraj
    @iamshubhamswaraj ปีที่แล้ว

    I want to bypass MFA under trusted IP network. Set conditional access policy and added my IP as trusted ip still facing the MFA prompt.

  • @user-eu2yf6ij2t
    @user-eu2yf6ij2t 2 ปีที่แล้ว +3

    Yeah, I'm gonna need nobandwidth intro music bro ;)

  • @cgaz9088
    @cgaz9088 2 ปีที่แล้ว +1

    Great video, great tool, a great addition to my toolbox! Thanks for the hard work

  • @michaelrogers2011
    @michaelrogers2011 ปีที่แล้ว

    Solid breakdown, thanks Beau.

  • @SumanRoy.official
    @SumanRoy.official 2 ปีที่แล้ว +1

    Wonderful video, totally an uncommon topic , subbed

  • @patrick__007
    @patrick__007 2 ปีที่แล้ว

    Can you do this in bulk? Instead per user per group per instance

  • @user-ty3iy8bk2l
    @user-ty3iy8bk2l ปีที่แล้ว

    Amazing video. Exactly what I was looking for.
    Subbed

  • @arjanvanveen3312
    @arjanvanveen3312 ปีที่แล้ว

    Is there a way to bypass my antivirus? This script contains malicious content and has been blocked by your antivirus software.

  • @nattsvart199
    @nattsvart199 2 ปีที่แล้ว

    Great video. Please do more mfa hacking and protecting.

  • @nmelanson75
    @nmelanson75 2 ปีที่แล้ว

    Does not work for me for Import I get a The ampersand (&) character is not allowed.

  • @eslamkamal1704
    @eslamkamal1704 2 ปีที่แล้ว +1

    Great content as usual 👏👏
    what is the best way to perform OPSEC during Azure Pentesting for example!!

  • @LukePWilkinsVids
    @LukePWilkinsVids 2 ปีที่แล้ว

    Brilliant information! Thank you

  • @prisa1590
    @prisa1590 2 ปีที่แล้ว +1

    Very interesting! Nice video.

  • @patrick__007
    @patrick__007 2 ปีที่แล้ว

    A great video. Thanks voor sharing.

  • @GisselleGuzman-pk8ui
    @GisselleGuzman-pk8ui ปีที่แล้ว

    hehehhe it's WORKING!! :) THANKS!! for creating this powershell script ..liked and subscribed

    • @anonymous-zi1pw
      @anonymous-zi1pw ปีที่แล้ว

      hi can you help me authenticate my account?

  • @australiansango
    @australiansango 2 ปีที่แล้ว +1

    Great video.

  • @socbrian
    @socbrian 2 ปีที่แล้ว

    Thanks for the video and tool. What if the company uses a federation service like Ping/Okta, I assume your tool wouldn't support that as the fields to stuff username / password would be different than MS's login screens

    • @wunderwuzzi3113
      @wunderwuzzi3113 2 ปีที่แล้ว +1

      Common misconfig includes ROPC working (e.g. MFA enforced at identity provider, but not in AAD) - so ROPC attack works and AAD gives out access token.

    • @anonymous-zi1pw
      @anonymous-zi1pw ปีที่แล้ว

      hi bro, did you get how to authenticate mfa? i need help

  • @MichaelToub
    @MichaelToub ปีที่แล้ว

    Great Video!!

  • @vicariousphoto
    @vicariousphoto 2 ปีที่แล้ว +1

    Spreadin them sheets 😎

  • @Boolap1337
    @Boolap1337 2 ปีที่แล้ว

    Cool

  • @lewiskelly14
    @lewiskelly14 2 ปีที่แล้ว

    The title should be clearer that this is for cloud and doesn't apply to Windows Server