Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication

5 Likes

machine ID and tenant ID. How can someone „easily“ get these if they don‘t have access to an enrolled device in the AAD forest?

I am not sure about the machine ID.

The tenant ID is often seen in user-facing URLs. It is not secret.

Is this only an issue if you use OneDrive cloud services, or any cloud service?

It is for MDfE, not for consumer version

1 Like