Executive Summary
A critical attack path has been identified where threat actors, including the suspected Russian state-aligned group Storm-2372, bypass Microsoft Entra ID (Azure AD) Conditional Access (CA) policies. By exploiting the Device Registration Service (DRS), attackers can register 'phantom devices' that lack physical hardware, such as a Linux laptop masquerading as a Windows endpoint. This allows for the generation of Primary Refresh Tokens (PRTs) with fraudulent claims of device health and compliance.
Technical analysis shows that attackers can further exploit gaps in Microsoft Intune enrollment by claiming hybrid domain-join status. Because Intune may treat missing health attestation data as 'not applicable' rather than non-compliant, these phantom devices can achieve a compliant status. This grants unauthorized access to internal enterprise applications and allows for extensive directory enumeration via the Graph API.
The business impact is severe, as it renders a primary cloud security pillar—device-based trust—ineffective. Organizations with hybrid identity environments are particularly at risk, especially those with privileged roles synced from on-premises AD, as compromising these accounts provides a direct path to full cloud tenant takeover.
