Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft patches NoAuth vulnerability, blocking account takeover attacks

Microsoft patches NoAuth vulnerability, blocking account takeover attacks

OnMSFT Staff OnMSFT Staff
July 11, 2023
2 min read

In this article

  • Terms you should know to understand NoAuth better
    • OpenID Connect (OIDC)
    • Azure Active Directory (Azure AD)
    • Identity Provider (IdP)
    • Open Authorization (OAuth)

As reported by Security Boulevard, a vulnerability has been discovered in the Microsoft Azure Active Directory (AD) Open Authorization (OAuth) process that could allow hackers to take complete control of user accounts.

The vulnerability, dubbed “NoAuth” by researchers from Descope, a California-based identity and access management service, affects multi-tenant OAuth applications within Azure AD. NoAuth is an authentication implementation flaw that allows attackers to modify the email attribute under the “Contact Information” section in Azure AD accounts. By exploiting the “Log in with Microsoft” feature, malicious actors can then compromise victim accounts.

To exploit NoAuth, an attacker would first need to create an Azure AD admin account. They would then modify the email address associated with this account to match the email address of the victim they want to target.

Once the attacker has modified the email address, they can then use the “Log in with Microsoft” feature to log in to any vulnerable application or website as the victim. This would give the attacker full control of the victim’s account, including access to their data and passwords.

Terms you should know to understand NoAuth better

OpenID Connect (OIDC)

OpenID Connect (OIDC) is an open authentication protocol that builds on the OAuth 2.0 architecture. OIDC is designed to be used by consumer-facing applications, and it allows users to access multiple websites with just one sign-on (SSO).

Azure Active Directory (Azure AD)

Azure Active Directory (Azure AD) is a cloud-based identity and access management (IAM) service that helps organizations manage user access to applications and resources. Azure AD uses OAuth 2.0 and OpenID Connect (OIDC) to provide a secure and convenient way for users to sign in to applications and websites.

Identity Provider (IdP)

Identity providers (IdPs) are a critical part of the OAuth and OIDC authentication process. An IdP is a trusted third party that stores and verifies user identities. When a user signs in to an application or website that uses OAuth or OIDC, the application or website redirects the user to the IdP’s login page. The IdP then validates the user’s credentials and, if successful, issues an access token to the application or website. The application or website can then use the access token to access the user’s protected resources.

Open Authorization (OAuth)

Open Authorization (OAuth) is an open, token-based authorization framework that allows users to grant access to their private resources to third-party applications without sharing their passwords or other sensitive information. For example, a Facebook user can authorize Medium to access their profile, read their posts, or post to their feed without having to provide Medium with their Facebook login information.

Related

Share this article:
Previous Article Microsoft lays off hundreds of employees, just six months after the company axed 10,000 jobs Next Article (Extremely) dedicated fan writes 1,000 page Starfield compendium

Related Articles

New Rowhammer Attacks Turn NVIDIA GPUs Into a System-Level Security Risk

April 4, 2026
Titan Army U275M could push gaming monitors to 1060Hz with dual-mode display

Titan Army U275M could push gaming monitors to 1060Hz with dual-mode display

April 4, 2026

New Intel Leak Shows Bigger Nova Lake Desktop CPU with 44 Cores

April 4, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • New Rowhammer Attacks Turn NVIDIA GPUs Into a System-Level Security Risk
  • Titan Army U275M could push gaming monitors to 1060Hz with dual-mode display
  • New Intel Leak Shows Bigger Nova Lake Desktop CPU with 44 Cores
  • NVIDIA Neural Rendering Reduces VRAM From 6.5GB to 970MB Without Losing Detail
  • H.264 Licensing Fees Rise to $4.5 Million for Streaming Platforms in 2026

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • New Rowhammer Attacks Turn NVIDIA GPUs Into a System-Level Security Risk
  • Titan Army U275M could push gaming monitors to 1060Hz with dual-mode display
  • New Intel Leak Shows Bigger Nova Lake Desktop CPU with 44 Cores
  • NVIDIA Neural Rendering Reduces VRAM From 6.5GB to 970MB Without Losing Detail
  • H.264 Licensing Fees Rise to $4.5 Million for Streaming Platforms in 2026

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy