𝗢𝘂𝘁𝘁𝗮𝗧𝘂𝗻𝗲: 𝗧𝗵𝗲 𝘀𝗼𝗿𝘁𝗮, 𝗻𝗼𝘁-𝗿𝗲𝗮𝗹𝗹𝘆, 𝗳𝗶𝘅
Earlier this year, I disclosed a security flaw in Microsoft Intune’s Conditional Access device filtering — where attackers with local admin rights could 𝙨𝙥𝙤𝙤𝙛 𝙙𝙚𝙫𝙞𝙘𝙚 𝙥𝙧𝙤𝙥𝙚𝙧𝙩𝙞𝙚𝙨 like device.model to 𝙗𝙮𝙥𝙖𝙨𝙨 𝙥𝙤𝙡𝙞𝙘𝙮 𝙚𝙣𝙛𝙤𝙧𝙘𝙚𝙢𝙚𝙣𝙩.
At first, it was marked “𝘽𝙮 𝘿𝙚𝙨𝙞𝙜𝙣.”
Then “𝙈𝙤𝙙𝙚𝙧𝙖𝙩𝙚 𝙨𝙚𝙫𝙚𝙧𝙞𝙩𝙮.”
Now, Microsoft says it’s “𝙛𝙞𝙭𝙚𝙙.”
𝗪𝗵𝗮𝘁 𝗰𝗵𝗮𝗻𝗴𝗲𝗱?
• Documentation now warns that 𝙨𝙤𝙢𝙚 𝙙𝙚𝙫𝙞𝙘𝙚 𝙥𝙧𝙤𝙥𝙚𝙧𝙩𝙞𝙚𝙨 𝙖𝙧𝙚 𝙪𝙣𝙩𝙧𝙪𝙨𝙩𝙚𝙙
• UX nudges were added in the CA policy editor and dashboard
• My name will appear in the MSRC researcher acknowledgements
𝗪𝗵𝗮𝘁 𝗱𝗶𝗱𝗻’𝘁 𝗰𝗵𝗮𝗻𝗴𝗲?
• 𝙉𝙤 𝙩𝙚𝙘𝙝𝙣𝙞𝙘𝙖𝙡 𝙘𝙤𝙣𝙩𝙧𝙤𝙡𝙨 prevent tampering
• Attackers can still 𝙢𝙤𝙙𝙞𝙛𝙮 𝙧𝙚𝙜𝙞𝙨𝙩𝙧𝙮 𝙫𝙖𝙡𝙪𝙚𝙨 and pass Conditional Access checks
• 𝘿𝙚𝙫𝙞𝙘𝙚 𝙩𝙧𝙪𝙨𝙩 𝙞𝙨 𝙨𝙩𝙞𝙡𝙡 𝙬𝙧𝙞𝙩𝙖𝙗𝙡𝙚 𝙗𝙮 𝙩𝙝𝙚 𝙙𝙚𝙫𝙞𝙘𝙚
New blog post here →
https://cirriustech.co.uk/blog/outtatune-tunedout/
If you rely on Intune or Entra for Zero Trust enforcement, 𝗿𝗲𝗮𝗱 𝘁𝗵𝗶𝘀.
And maybe… stop trusting the registry.