Varonis Discloses TrustSink Entra Password-Capture Technique
Varonis disclosed TrustSink, a post-compromise Microsoft Entra method that uses a rogue MFA provider to capture passwords during normal sign-in.
Varonis Threat Labs disclosed TrustSink on 28 September 2026 as a post-compromise technique against Microsoft Entra External Authentication Methods, not an initial-access method. An attacker who already holds Global Administrator or Authentication Policy Administrator rights registers a rogue external OpenID Connect provider. During an otherwise normal sign-in, the user sees a lookalike Microsoft password page that records the password—and, according to one report, the timestamp and source IP—while the provider returns a signed JWT so Entra treats MFA as successful and finishes the login with no error. Varonis demonstrated the technique in a test Entra tenant with a Python and FastAPI server. The reports agree that the rogue provider must be removed before credentials are rotated, but they differ on what happens if it stays: one says password resets fail, and the other says a later reset can be captured again. Recommended defenses are auditing and monitoring Entra logs for new external authentication methods, least-privilege admin roles, and phishing-resistant sign-in such as FIDO2 or Windows Hello.
- Varonis Threat Labs disclosed TrustSink on 2026-09-28.
- It is a post-compromise technique, not initial access, and requires Global Administrator or Authentication Policy Administrator rights.
- It abuses Microsoft Entra External Authentication Methods by registering a rogue OpenID Connect provider.
- A lookalike Microsoft password page captures the password—one report also cites the timestamp and source IP—while a signed JWT lets Entra complete the login with no error.
- Varonis demonstrated the technique in a test Entra tenant using a Python and FastAPI server.
- Both reports say the rogue provider must be removed before passwords are reset; one says resets fail while it remains, the other says a later reset can be captured again.
- Cited defenses include auditing Entra logs for new external authentication methods, least-privilege admin roles, and FIDO2 or Windows Hello.
Coverage timelineoldest first · each row is one article
- · 1d agoMicrosoft Entra TrustSink Attack Uses Rogue MFA Provider to Steal Passwords
GBHackers· 62
Varonis disclosed TrustSink, a post-compromise Entra technique using a rogue MFA provider to steal passwords.
- · 1d agoTrustSink Attack Uses Rogue MFA Provider to Steal Microsoft Entra Passwords During Legitimate Logins
Cyber Security News· 62
Varonis disclosed TrustSink, a post-compromise Entra technique that steals passwords via a rogue MFA provider.