Microsoft says the maximum-severity Entra ID flaw is fully mitigated and needs no customer action.
Malware can borrow Windows Hello for Business keys to open a 90-day persistence channel into Entra ID.
Attackers used 3.7 million spoofed OAuth client IDs to enumerate Entra ID user accounts and map application ecosystems.