MFA Isn't the Finish Line

Researchers showed how somebody who already holds admin rights can bolt a fake MFA step onto a company's login and keep every password typed into it. Resetting the passwords doesn't help. That's the useful part.

Researchers at Varonis published a technique this month they call TrustSink. Put plainly: somebody who already controls an administrator account on your Microsoft login can add an extra step to everyone's sign-in, make it look exactly like Microsoft's own password box, and keep every password typed into it — in plain text, with a timestamp. The sign-in then completes normally. Nothing looks wrong to the person at the keyboard. Our interest, up front: we deploy and support Microsoft 365 for our clients, so this is our own house, not somebody else's. Read the first sentence again, though, because the precondition is the story. The technical part — you can skip this box Per Varonis Threat Labs (Elad Ghvarh, last updated September 16, 2026), building on earlier work by Dirk-jan Mollema. Microsoft Entra ID supports External Authentication Methods — third-party providers registered in the tenant's Authentication Methods Policy and integrated into the sign-in flow over OpenID Connect. Registering one requires creating an application, a service principal and a consent grant, and amending the policy: actions available only to a Global Administrator or an Authentication Policy Administrator. A rogue provider publishes a discovery document and a public key at its JWKS endpoint, which Entra retrieves and trusts. At the multi-factor step Entra redirects the browser to the attacker's server with the user's identity and a nonce; the server serves a replica of the Microsoft password prompt, stores what is typed, then mints a signed token asserting acr: possessionorinherence and amr: ["hwk"] and posts it back. Entra validates the signature against the key it was given and completes the sign-in. Varonis's detection guidance: watch for new entries in the Authentication Methods Policy, application registrations using Microsoft's external-authentication callback, service principals with unfamiliar reply URLs, and sign-in logs showing an unfamiliar issuer with hwk claims. Their remediation order is explicit — disable the external method and remove its application and service principal before resetting any credentials. Microsoft has published no classification of this technique that we could find. What that actually means An "external authentication method" is a legitimate feature: you can tell Microsoft's login system to trust an outside service to handle the second step. Plenty of companies use one on purpose. The attacker registers a fake one. Why the forged approval is accepted. Your login system checks the second step's signature against a key. The attacker supplied both the signature and the key. The checking isn't broken; the attacker was in a position to choose what gets checked. Why resetting doesn't work. The fake step is still bolted on. Everyone resets, everyone signs in, and it collects the new passwords the same way. Remove the fake step first, then reset — in that order, or you've done the work twice. The precondition is not a footnote To do any of this, the attacker has to already be a Global Administrator or Authentication Policy Administrator on your tenant. That is not a small door, and this is not "MFA is broken." Anyone telling you it is has an alert to sell you. It's also not a Microsoft defect. External authentication methods are a supported feature working exactly as documented, in the hands of somebody who shouldn't have the account. What it is is a demonstration of something worth internalising: almost all security advice is about keeping people out. Very little is about what somebody does in the hours after they're already in. Turning MFA on raised your floor. It did nothing about the administrator account — and the administrator account is the whole building. What to do Ask for the list of everyone who holds Global Administrator. Not a report — the list. It should be short, it shouldn't include anybody's ordinary daily account, and if producing it takes more than a day, that's the finding. Ask whether any external authentication method is registered on your tenant, and who added it. For most small businesses the answer is "none," and it's a ten-second check. Ask who gets told when that policy changes. If the answer is nobody, that's this month's thing to fix — not because of this technique, but because a change nobody sees is the shape of every one of these stories. And if you're ever in an incident: remove before you reset. It's the opposite of everyone's first instinct and the single most useful sentence in the research.