Security research has shown that attackers with low-privilege access to an active Windows user session can abuse Windows Hello for Business (WHFB) keys to authenticate to Microsoft Entra ID without the victim’s PIN, biometrics, or other presence checks. By invoking native Windows cryptographic interfaces from the compromised session, an attacker can use the victim’s hardware-backed key to sign authentication data, obtain Primary Refresh Tokens (PRTs), and generate WebAuthn/FIDO2 assertions. Related research presented on attacking PRTs through their macOS implementation underscores broader interest in how platform-specific authentication flows can be leveraged to access cloud identity tokens.
The Windows technique is described as a design-level weakness rather than a newly patched vulnerability, in part because WHFB supports scenarios such as Remote Desktop where direct user presence is not always enforced. The researcher also demonstrated that WHFB keys can function as passkeys to obtain tokens lacking a device ID claim, which can then be used to register a new device and establish persistence in the tenant. Defenders are advised to monitor Entra ID sign-ins that show Windows Hello for Business authentication without an associated device ID and to investigate suspicious new device registrations tied to affected accounts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
At Black Hat USA 2026, SpecterOps presented 'Pass-the-Passkey,' describing a Windows and Microsoft Entra ID attack chain in which retained authentication signatures could be replayed to impersonate privileged users while satisfying phishing-resistant MFA requirements. The Windows component was tracked as CVE-2026-34348, and Microsoft said it released a security update and applied mitigations for the reported issue.
A researcher described a technique to use Windows Hello for Business keys from a compromised user session to authenticate to Microsoft Entra ID, request Primary Refresh Tokens, and perform WebAuthn/FIDO2 authentication without the user's PIN or biometrics. The post also says minimal WebAuthn support was added to ROADtools and roadtx to enable WHFB-based authentication and outlines persistence via new device registration.
A Security Friends Research Blog post described a phishing technique targeting Windows Hello for Business. This represents an earlier technical disclosure related to WHFB abuse that predates the later Entra ID key-abuse and tooling research.
The researcher states that Microsoft fixed older Entra ID behavior that had allowed an existing device's Primary Refresh Token to be used to create a new device identity after it was reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcedirkjanm.io
Open sourceblog.fndsec.net
Open sourcetroopers.de
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.