AmberWolf Research
  • Home
  • Blog
  • Disclosure Policy
  • Main Site
to navigate to select ESC to close

Showing posts from Entra ID

  • Home
  • /   Categories
  • /   Entra ID
  • Adam Boylan Adam Boylan
  • David Cash David Cash
  • 23 Jun, 2026
    • Disclosure
    • Vulnerability
    • Bypass

Microsoft Graph API - Hidden Exclusions with Overly Scoped Permissions

Hidden exclusions in Entra ID Conditional Access policies let attackers bypass MFA and use an overly scoped Graph token to enumerate tenant data.

Read Article
  • Main Site
  • Privacy

Copyright AmberWolf 2024-2026