The promise of Microsoft Azure Active Directory’s Conditional Access is a strong one: to protect your company by restricting access to cloud and on prem apps to authorized users and devices, on the basis of policies you can define.
However, as is often the case, hackers have found ways around these protections.
Here is a little guide to answer your questions: what is Azure AD Conditional Access ? How can hackers bypass it ?
Conditional Access is a cornerstone of the zero trust cloud cybersecurity policy of a company.
Conditional Access adds an additional security layer by restring access to apps to trusted devices that comply with certain criteria. It’s based on the analysis of contextual elements and the subsequent application of rules.
It’s therefore paramount to correctly setup the rules to follow and the policies in the event of a failure to comply.

When a hacker will try to connect, once they have gathered credentials, they will be confronted with an error message.
The key for the hacker trying to connect is therefore to analyze the error message sent by the system to the user in the event of a failure to connect. This will provide insight into which policy is preventing the successful log-in.

But first of all, a hacker needs credentials.
Hackers have multiple techniques to get credentials:

Once they have these credentials, they can turn to bypassing Conditional Access.
As with every cybersecurity solution, a tool is only effective if it’s deployed correctly (this is true for every tool, from anti-spam to awareness training to setting up multi-factor authentication).
Among the set-up mistakes we often see, we can highlight:
Access conditions are a first filter. An example is to have to connect from pre-approved IP addresses (not mentioning the fact that this is particularly cumbersome…).
For a hacker, it’s necessary to validate these initial conditions.
And they can be bypassed. The techniques depend on the condition chosen and used.
Here’s an overview of some access conditions and the tactics hackers can use to bypass them.
User sign-in
Device platform
Location
Once access conditions have been bypassed, access might be granted.
But sometimes, hackers are then faced with access controls. These are a second layer of security, once that access conditions have been validated, and in the event of failure connection is refused.
Among the different access controls to validate (and bypass), we can highlight :
Multi-factor authentication (MFA)
MFA is probably the access control that is the most used. It adds a layer of protection by requiring a second authentication through an alternative channel (push notification on a mobile device, one-time code received via text message…). This is an excellent policy to adopt but it can be bypassed by hackers:
Hybrid Azure AD joined device
Intune compliant device
Azure’s Conditional Access adds guarantees regarding access authorizations on your network.
That being said, it’s important to take care of the set-up and to keep in mind that Conditional Access is not fail-proof due to the information (the error messages sent by the system can provide the hackers with precious indications) provided and to the possible ways the conditions can be bypassed.
A bit lost navigating all the different kinds of phishing cyberattacks? Here's a quick guide to give you an overview of each: phishing, spear-phishing, whaling, smishing, vishing.
LibraCyber se positionne comme le seul éditeur européen à combiner sécurité des emails privacy-first, alimentée par l'IA, et formation à la sensibilisation à la cybersécurité Paolo Frizzi est nommé CEO ; Gianni Baroni rejoint le conseil d'administration en tant que conseiller Le groupe réuni compte plus de 3 500 clients via un réseau de plus de 500 revendeurs et fournisseurs de services managés en Europe et à l'international
What is the right frequency and timing of your phishing simulation campaigns to make them the most effective? Mantra's data team has a look at this issue.