News: 1684431134

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft decides it will be the one to choose which secure login method you use

(2023/05/18)


Microsoft wants to take the decision of which multi-factor authentication (MFA) method to use out of the users' hands and into its own.

The software maker this week is rolling out what it calls system-preferred authentication for MFA, which will present individuals signing in with the most secure method and then alternatives if that method is unavailable.

Redmond first [1]unveiled the feature in a disabled state in April and is now making it generally available to all commercial users through the Azure Portal or Graph APIs, with the decision whether to enable it for tenants now resting with administrators.

[2]

That said, in July Microsoft will make system-preferred authentication a default feature in its Azure Entra portfolio for all user accounts, with more information coming out next month.

[3]

[4]

The goal is to shore up security by not only delivering new features to harden products and services but to, at times, strong-arm people into using them.

More security, fewer problems?

"This system prompts the user to sign in with the most secure method they've registered and the method that's enabled by admin policy," Alex Weinert, vice president and director of identity security at Microsoft, wrote in a [5]blog post . "This will transition users from choosing a default method to use first to always using the most secure method available. If they can't use the method they were prompted to use, they can choose a different MFA method to sign in."

If the new feature is enabled, Azure Active Directory reviews the authentication methods that have been registered for a user account and selects the most secure route. The list of preferred methods starts with temporary access pass then goes, in order, to certificate-based authentication, FIDO2 security keys, Microsoft Authenticator push notifications, and a time-based one-time password. The last is a phone.

Redmond noted that FIDO2 security keys on mobile devices and registration for certificate-based authentication aren't supported because a problem arises when system-preferred authentication is enabled. The company didn't go into details about the issue, but said a fix is coming.

[6]

Weinert pointed to the "ever-changing threat landscape" as a key reason for enabling system-preferred authentication for MFA.

Microsoft's over-arching goal is to eventually [7]do away with usernames and passwords as an authentication method and migrating to other options, such as biometrics. However, until then, MFA is a key tool for verifying the user is who they say they are.

Earlier this month, Redmond [8]hardened Authenticator push notifications by enforcing a number-matching step, a way to push back against attackers looking to get through multiple authentication methods by using MFA fatigue, a social engineering technique. Miscreants using stolen credentials will try to overwhelm potential victims by rapidly and repeatedly sending out push notifications asking for login approval.

Looking at you, MitM

System-preferred authentication isn't the only security feature Microsoft is pushing out this week.

[9]How Microsoft hopes to tame large language models with Guidance

[10]Microsoft tries a deeper dive into Azure Firewall traffic

[11]EU monopoly cops probe complaints about Microsoft Azure

[12]Microsoft will upgrade Windows 10 21H2 users whether they like it or not

The company said it also is adding man-in-the-middle attacks to the list of security threats being addressed in its automatic attack disruption tool in Microsoft 365 Defender. At its [13]Ignite 2022 show last year, Microsoft talked about the tool, which aims to stop or reduce the damage caused by a cyberattack by automatically detecting and disrupting them.

The automatic attack disruption feature is aimed at corporate security operations centers (SOCs) and uses millions of data points and signals – across email, endpoints, collaboration tools, and other systems – and AI techniques to identify actives campaigns, including those involving ransomware – and take measures to isolate the device under attack from the network and suspend compromised accounts used by the attackers.

[14]

In February, the vendor [15]expanded the public preview of the feature to include business email compromise (BEC) and human-operated ransomware (HumOR) attacks. This week it added man-in-the-middle (MitM) – also known as adversary-in-the-middle, or AitM – attacks, in which the miscreant puts themselves in the middle of communications between two parties to intercept data, such as credentials and session cookies, traveling between them.

The criminals can then use the data to bypass MFA and launch other attacks.

Eyal Haik, senior product manager at Microsoft, wrote in a [16]blog post that "AiTM attacks are a widespread and can pose a major risk to organizations. We are observing a rising trend in the availability of adversary-in-the-middle… phishing kits for purchase or rent."

Microsoft's Threat Intelligence unit last month outlined a group it refers to as DEV-1101 that developed, advertised, supported, and sold several AitM phishing kits that others used when launching attacks. ®

Get our [17]Tech Resources



[1] https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-system-preferred-multifactor-authentication

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZGagA3DC5wHiK@qlECdqYwAAAAU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGagA3DC5wHiK@qlECdqYwAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGagA3DC5wHiK@qlECdqYwAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/ga-system-preferred-multifactor-authentication/ba-p/3773138

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGagA3DC5wHiK@qlECdqYwAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/11/07/microsoft_azure_phishing_mfa/

[8] https://www.theregister.com/2023/05/09/microsoft_authenticator_number_matching/

[9] https://www.theregister.com/2023/05/18/microsoft_guidance_project/

[10] https://www.theregister.com/2023/05/16/microsoft_azure_firewall_traffic/

[11] https://www.theregister.com/2023/05/16/eu_confirms_azure_complaints/

[12] https://www.theregister.com/2023/05/15/windows_10_21h2_support/

[13] https://www.theregister.com/2022/10/12/microsoft_ignite_security/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGagA3DC5wHiK@qlECdqYwAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://www.theregister.com/2023/02/24/microsoft_365_disrupt_attacks/

[16] https://techcommunity.microsoft.com/t5/microsoft-365-defender-blog/automatically-disrupt-adversary-in-the-middle-aitm-attacks-with/ba-p/3821751

[17] https://whitepapers.theregister.com/



At it again

steviebuk

Would be fine if their cocking MFA was stable which it isn't.

Re: At it again

Anonymous Coward

It's only secuity theatre anyway. It would be better if they actually made their products more secure.

biometrics?

stiine

I can hear the conversation now. "Hello, Microsoft? Yes, my local city government has fallen victim to a ransomware attack and my personal information, including iris and fingerprints were exfiltrated. I need to change my biometrics because they were compromised. What is your procedure for this? Surgery? New eyes and hands? Are you that fucking stupid?"

Re: biometrics?

MOH

-stupid +venal

WorkShyEU

And where does Microsoft store your biometric data.. Yeah in the US on their servers...Highest bidders get a peek

NoneSuch

"And where does Microsoft store your biometric data.. Yeah in the US on their servers...Highest bidders get a peek"

You assume they will only sell your info to a single company, once, do you?

Boris the Cockroach

With the NSA/CIA/FBI getting a look in first..... which then finds a match and then some suitable spam.

"Congratulations, as a valued m$ customer, we can give you a free trip to disney land florida from where ever you happen to be , with free limo from the airport to a hotel of our choosing, and then all cons accomedation, act now to claim your place"...

Adam JC

While I'm always quick to jump on the bandwagon, I have to chip in here.. Biometric data is stored on the local device, it's never broadcast off the device. This is why you can't reset biometric login methods using Azure/Entra but can clear the data and re-enroll if needs be.

Who's PC?

navarac

Again! Who's PC is it? Not Microsoft's, unless they are gifting me a new machine for Christmas!

Re: Who's PC?

MOH

Hooze

Re: Who's PC?

JamesTGrant

Hues

IT MAKES ME MAD when I go to all the trouble of having Marta cook up about
a hundred drumsticks, then the guy at Marineland says, "You can't throw
that chicken to the dolphins. They eat fish."

Sure they eat fish if that's all you give them! Man, wise up.
-- Jack Handey, The New Mexican, 1988.