Microsoft Quietly Closes Another Loophole for Tenant Domain Enumeration
Read OriginalMicrosoft has made a backend change to the legacy Azure Access Control Service (ACS) metadata endpoint, preventing unauthenticated users from enumerating all verified domains of an M365 tenant. This closes a significant OSINT and reconnaissance vector for attackers, aligning with recent similar changes to Exchange Online Autodiscover. The article discusses the security implications and directs legitimate administrators to use the authenticated Microsoft Graph API for domain queries.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser