OAuth ROPC Flow Abuse Enables Massive Azure Credential Spray
Attackers exploited the deprecated OAuth Resource Owner Password Credentials (ROPC) flow to bypass MFA protections across 64 organizations, compromising 78 accounts through over 81 million login attempts. The root failure was a misconfigured MFA policy that did not extend coverage to legacy OAuth authentication flows, creating a blind spot that rendered MFA ineffective for those pathways. This matters because organizations often assume MFA provides universal protection without auditing whether all authentication methods and flows are actually covered by that policy. Deprecated protocols like ROPC represent a known, documented risk that should be disabled unless absolutely necessary, as they inherently bypass modern security controls. This incident is a stark reminder that security controls must be validated holistically, not assumed to be comprehensive.
Tactical Insight
Immediate actions
- Audit and disable the OAuth ROPC authentication flow in Azure AD/Entra ID unless there is a documented, approved business requirement.
- Review all Conditional Access policies to ensure MFA enforcement explicitly covers legacy and non-interactive OAuth flows, not just modern browser-based sign-ins.
Long-term improvements
- Establish a formal process to identify and deprecate legacy authentication protocols across the environment on a recurring schedule.
- Enforce Conditional Access policies that block all legacy authentication methods by default, requiring exceptions to be explicitly approved and time-limited.
- Maintain an inventory of all authentication methods and flows in use, mapping each to the corresponding security controls that protect them.
Detection measures
- Configure SIEM alerting for anomalous login attempt volumes, especially originating from single ASNs or IP ranges, to detect credential spray patterns early.
- Enable and review Azure AD sign-in logs and risky sign-in reports regularly to identify accounts targeted by or succeeding through non-standard authentication flows.
- Integrate threat intelligence feeds to automatically flag or block known malicious ASNs (e.g., AS32167) at the network perimeter or identity provider level.