HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

OAuth Client ID Spoofing Enables Stealth Account Enumeration in Microsoft Entra ID

Proofpoint reports that attackers are forging OAuth client IDs to query Microsoft Entra ID, allowing them to enumerate user accounts and infer password validity without a successful sign‑in. This bypasses typical log‑based detection, highlighting the need for robust access‑control monitoring in SOC 2‑ready environments.

LiveThreat™ Intelligence · 📅 July 13, 2026· 📰 proofpoint.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
proofpoint.com

OAuth Client ID Spoofing Enables Stealth Account Enumeration in Microsoft Entra ID

What Happened — Proofpoint’s Threat Insight team identified a growing technique where attackers submit forged OAuth client IDs (the GUID that identifies an application) to Microsoft Entra ID’s token endpoint. By doing so they can enumerate user accounts and infer password validity without ever generating a successful sign‑in event. Multiple independent campaigns were observed using this method at scale.

Why It Matters for Compliance & Audit Readiness

  • The tactic bypasses traditional sign‑in log alerts, undermining the effectiveness of SOC 2 CC6.1 (Logical Access) monitoring and evidence‑collection requirements.
  • Continuous‑compliance programs must capture “application‑less” sign‑in events as audit evidence of attempted unauthorized access.
  • Verisq’s SOC 2 Access Controls capability provides automated log ingestion, anomaly detection, and ready‑to‑audit evidence for exactly this class of credential‑enumeration attempts.

Who Is Affected — Cloud‑based identity providers (e.g., Microsoft Entra ID), SaaS platforms that rely on OAuth 2.0, and any organization that integrates third‑party applications via OAuth.

Recommended Actions

  • Map the enumeration scenario to SOC 2 CC6.1/CC6.2 controls and update your access‑control monitoring policy.
  • Enable logging of sign‑in events that lack an associated application name and create alerts for such anomalies.
  • Periodically review registered OAuth client IDs and enforce least‑privilege registration.
  • Document detection rules and evidence collection in your continuous‑compliance repository.

Technical Notes

  • Attack vector: spoofed OAuth client_id passed to /common/oauth2/token using the Resource Owner Password Credentials (ROPC) flow.
  • No CVE is associated; the issue stems from Entra ID’s response behavior rather than a code flaw.
  • Data at risk: user account existence and password‑validation status, which can be leveraged for credential‑stuffing or phishing.

Source: Proofpoint Threat Insight – OAuth Client ID Spoofing

📰 Original Source
https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →