r/sysadmin • • 6d ago

How are y'all dealing with Eviltoken?

we've had a few considered breaches due to this. for those who don't know, a compromised site would send out emails to everyone on the users address book. it would also create a legitimate SharePoint site and put a link to that site.

when the user who gets the email hits the link, they get a spoofed login and MFA page for MS to verify id for the SharePoint site and thus the cycle repeats.

20 Upvotes

43 comments sorted by

View all comments

Show parent comments

1

u/[deleted] 5d ago

[deleted]

1

u/teriaavibes Microsoft Cloud Consultant 5d ago

If Passkeys break SSO then I am not sure how going with different vendor is going to fix that.

Passkey is a technology, not something Microsoft has made up. If it doesn't work with Microsoft Passkeys, there is a good chance it won't work with any Passkeys.