The Microsoft ID vulnerability enters allows the complete acquisition of the account, and just requires any effort




  • 10% of the more than 150,000 SAAS applications offered could be affected by the Vulnerability of Enter ID
  • First it was revealed in 2023, but many applications are still affected
  • Application suppliers must issue patches or their risk account control

Semperis has published a new research that discovers a severe defect in the identification of Microsoft, called Noauth, and its effects could cover 10% of SAAS applications worldwide.

Vulnerability implies an authentication failure of cross tenant that affects the integrations of Enter ID: the attackers could execute the complete acquisition of the account only access to an entry tenant and the email of the victim.

Leave a Comment

Your email address will not be published. Required fields are marked *