Researchers reported that Microsoft Entra ID’s legacy WS-Trust autologon endpoint for Seamless SSO can be abused to conduct password-spraying attacks with reduced defensive visibility. Testing found the usernamemixed endpoint remained reachable for older Office 2013-era clients, did not appear to trigger expected Smart Lockout protections, and omitted failed attempts from standard Entra ID sign-in logs. The endpoint also returned distinct AADSTS error codes that let attackers distinguish invalid passwords from valid credentials that were later blocked by MFA or Conditional Access, enabling efficient credential validation without full account access.
The activity aligns with ATT&CK techniques for Password Spraying and abuse of Valid Accounts, including default or legacy authentication paths that permit legitimate-looking logons once credentials are known. Defenders were advised to disable the WS-Trust usernamemixed endpoint, block legacy authentication through Conditional Access, monitor the Unified Audit Log for autologon requests, and use detections for repeated failed logons from a single IP across multiple users—similar to Okta analytics that flag more than five invalid authentication attempts from one source as suspicious spraying behavior.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Varonis published research describing how Microsoft Entra ID's legacy WS-Trust autologon endpoint can be used for password spraying that bypasses expected Smart Lockout behavior, omits failed attempts from standard sign-in logs, and reveals valid passwords through distinct AADSTS responses. The article also recommends disabling the usernamemixed endpoint, blocking legacy authentication, and monitoring the Unified Audit Log.
Splunk removed the detection 'Multiple Okta Users With Invalid Credentials From The Same IP' from its Threat Research content library in version 5.2.0. The company said it was replaced with 'Okta Multiple Users Failing To Authenticate From Ip' because detections were updated for new search logic and field names.
The Varonis article cites Secureworks Counter Threat Unit research documenting that failed authentications against the autologon flow were not visible in standard Entra ID sign-in logs. It notes Microsoft classified this behavior as 'by design.'
MITRE published the ATT&CK entry for Valid Accounts: Default Accounts, describing how adversaries abuse default accounts for initial access, persistence, privilege escalation, and defense evasion. The entry includes examples such as built-in OS accounts, factory-set credentials, and ESXi's vpxuser account.
The Varonis article cites prior research by Dr. Nestori Syynimaa documenting user enumeration against Microsoft Seamless SSO. This is referenced as earlier public research relevant to the WS-Trust autologon issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
varonis.com
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.