Azure AD Conditional Access Bypass via Phantom Devices
Score: 8/10

Azure AD Conditional Access Bypass via Phantom Devices

The Storm-2372 threat actor and security researchers bypass Microsoft Entra ID Conditional Access by registering phantom devices and spoofing Intune compliance claims.

Executive Summary

A critical attack path has been identified where threat actors, including the suspected Russian state-aligned group Storm-2372, bypass Microsoft Entra ID (Azure AD) Conditional Access (CA) policies. By exploiting the Device Registration Service (DRS), attackers can register 'phantom devices' that lack physical hardware, such as a Linux laptop masquerading as a Windows endpoint. This allows for the generation of Primary Refresh Tokens (PRTs) with fraudulent claims of device health and compliance.

Technical analysis shows that attackers can further exploit gaps in Microsoft Intune enrollment by claiming hybrid domain-join status. Because Intune may treat missing health attestation data as 'not applicable' rather than non-compliant, these phantom devices can achieve a compliant status. This grants unauthorized access to internal enterprise applications and allows for extensive directory enumeration via the Graph API.

The business impact is severe, as it renders a primary cloud security pillar—device-based trust—ineffective. Organizations with hybrid identity environments are particularly at risk, especially those with privileged roles synced from on-premises AD, as compromising these accounts provides a direct path to full cloud tenant takeover.

Key Details

Threat Name

Storm-2372 Azure AD Bypass

Affects

—

Adversary

Storm-2372

Malware/Tools

Storm-2372, AADInternals

Report Score

8out of 10
Quality Score
Good
IOC Quality4
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure9
Technical Depth9

Sources