Exploiting PTA Credential Validation: A New Microsoft Attack Surface

No ratings

Presented at RSAC 2025 by

New research has discovered a vulnerability in Microsoft Entra ID’s Pass-Through Authentication (PTA), allowing attackers to hijack the agents and exploit credential validation mechanisms. Explore findings outlining how attackers can intercept and manipulate authentication requests, bypassing security controls and leading to unauthorized access to hybrid and cloud environments.