TrustSink Attack Exploits Microsoft Entra MFA for Password Theft
A novel 'TrustSink' attack leverages Microsoft Entra's external authentication methods to steal user passwords during legitimate MFA logins by registering a rogue provider.

A sophisticated identity attack, dubbed TrustSink, has been identified that weaponizes Microsoft Entra's multi-factor authentication (MFA) process to steal user passwords. Unlike traditional phishing attacks that rely on fake websites or malicious links, TrustSink operates by registering a rogue authentication provider within a victim's Entra tenant. This malicious provider intercepts the user's login flow after they have successfully completed their initial MFA challenge, presenting a convincing, pixel-accurate replica of Microsoft's own password prompt.
The attack requires an adversary to first gain privileged access within the Microsoft Entra environment, holding roles such as Global Administrator or Authentication Policy Administrator. Once this prerequisite access is established, the attacker can modify authentication policies, register a malicious application and service principal, grant it necessary consent, and expose the rogue provider over HTTPS. This setup allows the attacker to manipulate the authentication process without raising immediate suspicion from the user or standard security monitoring.
TrustSink specifically abuses Microsoft Entra's External Authentication Method (EAM) feature. During an MFA flow, Entra can be configured to call an external provider. In this attack, the malicious provider sends a signed response to Entra indicating that the authentication check has succeeded, while simultaneously displaying a fake password page to the user. After the user enters their credentials into this deceptive prompt, the attacker's provider silently captures the password before automatically redirecting the user to their intended application, completing the login process seemingly without error.
Researchers at Varonis, who discovered and named the technique, demonstrated that this method is designed as a post-compromise persistence mechanism. A critical aspect of TrustSink is its ability to persist even after a user resets their password. Because the rogue authentication provider remains configured within Entra, it can capture the newly reset password during the next login attempt, effectively bypassing the password reset as a remediation step.
The attack's reliance on Entra's trust relationships for external authentication makes it particularly insidious. The malicious provider publishes a discovery document and a public signing key that Entra uses to validate its responses, creating a veneer of legitimacy. Entra then accepts a signed token from this provider, which includes claims indicating a successful hardware-key check, further masking the credential theft.
Security teams are advised to implement robust monitoring for suspicious changes within their Entra environments. Key indicators include the addition of new externalAuthenticationMethodConfiguration entries, unexpected application registrations, service principal creations, consent grants, or unusual redirect URIs, especially when these actions occur in rapid succession. Sign-in logs can also reveal the rogue provider's issuer URL and report hardware-key-related claims without a genuine key ceremony.
To mitigate TrustSink, organizations should disable and remove the malicious external method and its associated configurations. This includes removing the related app registration, service principal, signing keys, consent grants, and redirect URIs. Responders must also identify and reset credentials for any users who authenticated through the compromised provider and thoroughly examine their subsequent activity. The adoption of phishing-resistant authentication methods, such as FIDO2 security keys or Windows Hello for Business, is strongly recommended to reduce reliance on passwords and make unexpected password prompts more easily identifiable as anomalous.