Daniel 3/16/2026

Microsoft Quietly Closes Another Loophole for Tenant Domain Enumeration

Read Original

Microsoft has made a backend change to the legacy Azure Access Control Service (ACS) metadata endpoint, preventing unauthenticated users from enumerating all verified domains of an M365 tenant. This closes a significant OSINT and reconnaissance vector for attackers, aligning with recent similar changes to Exchange Online Autodiscover. The article discusses the security implications and directs legitimate administrators to use the authenticated Microsoft Graph API for domain queries.

Microsoft Quietly Closes Another Loophole for Tenant Domain Enumeration

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser