CTD-000095

Entra ID tenant vulnerable to MFA fatigue attacks via voice authentication method

High
Entra ID
Credential Access
v22

Signature Identity

CTD-000095
Threat ID
22
Version
IOE
Indicator Type

Threat Description

With increasing adoption of strong authentication, multi-factor authentication (MFA) fatigue attacks (aka, MFA spamming) have become more prevalent. These attacks rely on the user’s ability to approve a simple voice notification that doesn’t require the user to have context of the session they are authenticating. Anytime users are doing “press hash key” or “enter your PIN to approve” instead of entering a code they see on-screen, they are doing simple approvals. Microsoft’s studies show that about 1% of users will accept a simple approval request on the first try. That’s why it’s critical to ensure that users must enter information from the login screen and that they have more context and protection. Number matching with “type the code” experience prevents accidental approval by requiring the user to type in a two-digit code from the login screen to their Authenticator app. If the user didn’t initiate the sign-in, they won’t know the two-digit code, thereby requiring the threat actor to share the two-digit code in a separate channel, which the user shouldn’t accept.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To disable authentication method for all users with Microsoft Entra admin center:

  1. Find and select Microsoft Entra authentication methods using search.
  2. Click on Policies.
  3. Select Voice call.
  4. Move the switch to Disable state.
  5. Press Save.

Frequently Asked Questions

What does Entra ID tenant vulnerable to MFA fatigue attacks via voice authentication method mean?

When voice authentication is enabled for all users in Microsoft Entra, it allows users to approve simple voice notifications without entering information from the login screen. This can be exploited by attackers conducting multi-factor authentication (MFA) fatigue attacks, increasing the likelihood of account takeover when credentials are stolen or guessed.

This vulnerability is rated high severity because it enables attackers to conduct MFA fatigue attacks, which can lead to unauthorized access. When voice authentication is enabled for all users, it increases the risk of users approving malicious voice notifications without context, allowing attackers to bypass usual security measures and gain access to user accounts.

Attackers can exploit this vulnerability by sharing a two-digit code with the victim in a separate channel and tricking them into approving the malicious voice notification. This allows attackers to bypass usual security measures, gain access to user accounts, and potentially escalate privileges.

Cayosoft Guardian detects this vulnerability by continuously monitoring the configuration of Microsoft Entra authentication methods. When it finds that voice authentication is enabled for all users, Guardian flags this as a security issue and provides visibility into the setting so administrators can take corrective action.

Cayosoft Guardian helps reduce the risk by alerting administrators to disable voice authentication for all users in Microsoft Entra admin center, providing visibility into the setting and supporting investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
MFA Tenant-wide
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical