TrustSink PoC shows rogue MFA provider registration via Entra
Varonis Threat Labs released a proof‑of‑concept called TrustSink that demonstrates how a compromised Azure AD (Microsoft Entra) Global Administrator can add a malicious external MFA provider.
Why it matters
External MFA providers are trusted by Entra to complete the second factor. If an attacker can register one, they sit in the middle of the authentication chain.
Technical walk‑through
The attack proceeds in two steps:
- Gain control of a highly privileged Entra account, such as a Global Administrator.
- Use the compromised account to add an external MFA provider through the Authentication Methods Policy.
Once registered, the provider is invoked during every login that requires MFA. The PoC used Microsoft’s own login.microsoftonline.com flow to illustrate the process.
Who is at risk
Any organization that relies on Microsoft Entra and has enabled external MFA providers – including those using FIDO2 or Windows Hello for Business – could be exposed if a privileged account is breached.
Defensive recommendations
Varonis advises:
- Audit the list of external MFA providers regularly and remove any that are not explicitly approved.
- Monitor changes to the Authentication Methods Policy for additions of new providers.
- Enforce strict controls and MFA on privileged Entra accounts to reduce the chance of compromise.
The original brief appeared on BleepingComputer on 22 September 2026.