Researchers have uncovered a novel identity-based attack dubbed “TrustSink” that exploits Microsoft Entra’s multi-factor authentication (MFA) flow to harvest user passwords—without the user knowing. Instead of leading victims to a bogus login page, this approach embeds a realistic password prompt within the standard Microsoft Entra sign-in process. Victims go through MFA and reach the application as usual, yet a bogus provider captures their real password during the final login stage. A password reset alone won’t eradicate the vulnerability, since the rogue authentication provider stays in place and can capture credentials again on future logins.
How TrustSink Works
The attack begins after an adversary gains access to a privileged Entra account—such as Global Administrator or Authentication Policy Administrator. Once inside, the attacker alters authentication policy settings, registers an external app and service principal, and exposes a rogue authentication method over HTTPS.
TrustSink abuses an External Authentication Method (EAM) within Microsoft Entra. During login, the malicious provider returns a signed success message to Entra, while simultaneously presenting the user with a password prompt that mimics Microsoft’s own login interface. The victim re-enters their password, which the rogue provider invisibly logs before letting the login process conclude as expected.
Detection & Mitigation Advice
Defense teams are urged to audit every entry in the externalAuthenticationMethodConfiguration setting, looking for unauthorized additions. Sign-in logs should be examined for unfamiliar issuers or bogus hardware-key claims in contexts where no such check should exist. Unexpected app registrations, permission grants, group assignment changes, or redirect URI modifications — especially when they happen in rapid succession — are strong warning signals.
If TrustSink is detected, organizations should remove the rogue external method and any group associations, then dismantle the related app registration, service principal, signing key, consent grant, and redirect URI. Following that, reset passwords of any accounts that used the provider and review their recent activity.
Why It Matters—and What’s Next
The research strongly recommends transitioning users—particularly administrators—away from reusable passwords and toward phishing-resistant options like FIDO2 security keys or Windows Hello for Business. Reducing reliance on standard passwords helps make any unsolicited password prompts during MFA much more noticeable.
Restricting standing enrollments for privileged roles, enforcing least privilege across global administrator-type accounts, and conducting frequent audits can limit the attack surface. Because the TrustSink technique was designed as a persistence mechanism—not an initial breach method—its danger lies in how it endures beyond typical defenses.
What this means:TrustSink shows that even steps designed to fortify login flows—like MFA—can be manipulated if trust is misplaced inside the identity infrastructure itself. Organizations should treat their external authentication methods with the same scrutiny as IAM policies or device certificates. Watch for unexpected authentication configurations, new apps gaining consent, or mismatched issuer claims. Investing in password-less and phishing-resistant identity tools may not just be good hygiene—it could be essential.