Skip to content

Latest commit

 

History

History
5 lines (3 loc) · 229 Bytes

azuread.md

File metadata and controls

5 lines (3 loc) · 229 Bytes

nOAuth attack on AzureAD

Changing the email address of a user to one not belonging to the tenant is trivial in Microsoft Azure. The image below shows a spoofed email configured for the user account.

screenshot