BSides Canberra 2026

Rawson Wade

Rawson is a Senior Security Engineer at Modern42, where he leads a team of specialist Microsoft Entra developers and engineers building secure IAM ecosystems for government, health, and banking. His expertise sits in the complex end of authentication, with deep domain knowledge across IAM, Workload Identities and CIAM.


Session

09-25
10:00
55min
Exploiting the Microsoft 365 Substrate: How their OAuth Clients Became an MFA Bypass Across Enterprise Tenants
Rawson Wade

Every time you sign in to Microsoft 365, a quiet exchange happens behind the scenes. Entra ID issues a token, and a sprawling backend known as the Microsoft 365 Substrate decides what that token is allowed to do. Most of that machinery is invisible, well trusted, and rarely questioned, which makes it exactly the kind of place worth questioning.

Tucked inside those tokens are claims that downstream services lean on to decide whether you really are who you say you are, and whether you have done the things, like MFA, that policy demands. But what happens when two parts of Microsoft's own platform disagree about what a token has actually proven?

In this talk I'll show how an asymmetry of authorisation between Microsoft Entra ID single sign-on and the Microsoft 365 Substrate led to enterprise account compromise on accounts where MFA should have been enforced.

You'll see how the now-patched, Important-rated vulnerability I found works end to end, starting from where it began and following how a small finding grew into something much larger.
I'll trace how misplaced trust in the claims of an access token turned into enterprise-scale data exfiltration, show some of the stranger quirks of the Substrate I ran into along the way, and explain why the asymmetry existed in the first place, with Windows Search, Microsoft Edge and Microsoft Teams all turning out to be the stars of the show.

Finally, we'll change lens and see why this isn't just a Microsoft bug, and why it might be a cautionary tale for the applications you're building. We'll walk through the common OAuth and OIDC gotchas: where developers over-trust the IdP, which claims actually carry the guarantees you think they do, and why a growing number of application providers are taking MFA enforcement into their own hands rather than waiting on the IdP to do it for them.

Off-Main Track
Off-Main Track