BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidescbr.com.au//bsides-canberra-2026//talk//PZEVC
 X
BEGIN:VTIMEZONE
TZID:Australia/Sydney
BEGIN:STANDARD
DTSTART:20250925T000000
TZNAME:AEST
TZOFFSETFROM:+1000
TZOFFSETTO:+1000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20251005T030000
RDATE:20261004T030000
TZNAME:AEDT
TZOFFSETFROM:+1000
TZOFFSETTO:+1100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20260405T030000
RDATE:20270404T030000
TZNAME:AEST
TZOFFSETFROM:+1100
TZOFFSETTO:+1000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Exploiting the Microsoft 365 Substrate: How their OAuth Clients Be
 came an MFA Bypass Across Enterprise Tenants - Rawson Wade
DTSTART;TZID=Australia/Sydney:20260925T100000
DTEND;TZID=Australia/Sydney:20260925T105500
DTSTAMP:20260727T185452Z
UID:pretalx-bsides-canberra-2026-PZEVCX@cfp.bsidescbr.com.au
DESCRIPTION:Every time you sign in to Microsoft 365\, a quiet exchange hap
 pens behind the scenes. Entra ID issues a token\, and a sprawling backend 
 known as the Microsoft 365 Substrate decides what that token is allowed to
  do. Most of that machinery is invisible\, well trusted\, and rarely quest
 ioned\, which makes it exactly the kind of place worth questioning.\n\nTuc
 ked inside those tokens are claims that downstream services lean on to dec
 ide whether you really are who you say you are\, and whether you have done
  the things\, like MFA\, that policy demands. But what happens when two pa
 rts of Microsoft's own platform disagree about what a token has actually p
 roven?\n\nIn this talk I'll show how an asymmetry of authorisation between
  Microsoft Entra ID single sign-on and the Microsoft 365 Substrate led to 
 enterprise account compromise on accounts where MFA should have been enfor
 ced.\n\nYou'll see how the now-patched\, Important-rated vulnerability I f
 ound works end to end\, starting from where it began and following how a s
 mall finding grew into something much larger.\nI'll trace how misplaced tr
 ust in the claims of an access token turned into enterprise-scale data exf
 iltration\, show some of the stranger quirks of the Substrate I ran into a
 long the way\, and explain why the asymmetry existed in the first place\, 
 with Windows Search\, Microsoft Edge and Microsoft Teams all turning out t
 o be the stars of the show.\n\nFinally\, we'll change lens and see why thi
 s isn't just a Microsoft bug\, and why it might be a cautionary tale for t
 he applications you're building. We'll walk through the common OAuth and O
 IDC gotchas: where developers over-trust the IdP\, which claims actually c
 arry the guarantees you think they do\, and why a growing number of applic
 ation providers are taking MFA enforcement into their own hands rather tha
 n waiting on the IdP to do it for them.
LOCATION:Off-Main Track
URL:https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/PZEVCX/
END:VEVENT
END:VCALENDAR
