NetSPI researchers discovered that attackers can bypass Microsoft Entra Conditional Access Policies by abusing the Nested App Authentication OAuth flow…