Guardz, a cybersecurity company focused on empowering Managed Service Providers (MSPs) and IT professionals, has recently uncovered a sophisticated attack campaign targeting outdated authentication protocols in Microsoft Entra ID. The campaign, detected by Guardz's Research Unit (GRU), exploited legacy authentication methods, especially BAV2ROPC, to bypass modern security measures like Multi-Factor Authentication (MFA) and Conditional Access Policies. The attack, which was active from March 18 to April 7, 2025, serves as a warning to businesses that have not fully modernized their authentication frameworks. Read More









