Rogue MFA providers can quietly recapture changed passwords
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 23rd, 2026.
A rogue external authentication provider could steal passwords during apparently normal Microsoft Entra logins. The demonstrated technique requires an attacker to already control a highly privileged account, so this is a post-compromise method rather than a way to gain initial access. Once configured, the malicious provider inserts a convincing password prompt into the legitimate sign-in flow, captures the credential, and then completes the login normally. From the user’s perspective, nothing appears to have failed. Even a changed password can be captured again while the rogue provider remains registered.
That persistence means password resets alone won’t solve the problem. The malicious provider and its related application components have to be removed first. For leaders, external authentication integrations should be treated as privileged trust relationships with formal ownership and review. For defenders, important controls include monitoring authentication-policy changes and reducing standing access for Global Administrator and Authentication Policy Administrator roles. The larger lesson is that M F A can be undermined through trusted configuration after an administrative account is compromised. Remove any rogue provider and associated application components before resetting credentials or restoring user access.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.