Bypassing MFA: Legacy Protocols Expose Microsoft Entra ID to Attackers

Legacy Protocols Expose Microsoft Entra ID

Advanced Threat Campaign Exploits Microsoft Entra ID via Deprecated Protocols

Between March 18 and April 7, 2025, security researchers at Guardz uncovered a stealthy and highly automated attack operation aimed at Microsoft Entra ID. This campaign leveraged outdated authentication mechanisms that, despite being long flagged for deprecation, continue to persist in enterprise environments.

By targeting legacy protocols, attackers were able to sidestep modern defenses such as Multi-Factor Authentication (MFA) and Conditional Access—controls typically seen as the front line in identity protection. These vulnerabilities stemmed from continued reliance on insecure technologies like BAV2ROPC, IMAP4, POP3, and SMTP AUTH, which lack the protections embedded in contemporary authentication frameworks.

Although Microsoft has officially phased out or restricted many of these protocols, legacy system dependencies and operational inertia have left critical gaps in organizational security postures. These weaknesses are now being exploited by sophisticated actors using tailored methods.

Coordinated Attacks: Automation Meets Obsolescence

The Guardz team observed a multi-stage campaign involving more than 9,000 Exchange login attempts across a three-week window. Attackers launched low-volume reconnaissance efforts that gradually intensified, culminating in a dramatic surge of over 8,500 login attempts within a single 24-hour period (April 4–7). This pattern reflected calculated escalation and coordination across dozens of IP addresses, predominantly from Eastern Europe and Asia-Pacific regions.

Threat actors employed credential spraying and brute-force tactics, focusing particularly on endpoints still using legacy authentication paths. Alarmingly, approximately 90% of attack traffic zeroed in on Exchange Online—highlighting a strategic interest in intercepting email communications and potentially accessing sensitive business data or login tokens.

How BAV2ROPC Became the Perfect Entry Point

Central to the attackers’ strategy was the abuse of BAV2ROPC (Basic Authentication Version 2, Resource Owner Password Credential), a transitional protocol originally intended to ease movement toward OAuth 2.0. Instead of prompting users for interactive authentication, BAV2ROPC enables direct submission of credentials—silently converting them into access tokens.

This non-interactive process allows threat actors to bypass security challenges that would otherwise interrupt login attempts. No user prompts, no visible login flows, and no triggered alerts—just quiet access. Once attackers acquire credentials (often via phishing or breach reuse), they can leverage BAV2ROPC to gain entry without raising suspicion.

What makes this tactic particularly dangerous is its focus on administrative accounts. In one case, a single admin identity faced nearly 10,000 login attempts from over 400 unique IPs—within just 8 hours. The distributed nature of this assault underscores a clear evolution in attacker playbooks, where automation, legacy weakness, and targeted persistence converge.

More Articles & Posts