I finally came around and documented all the Conditional Access bypasses in a single blog post. It contains not only the documented bypasses, but also the results of new research.
#Entra#ConditionalAccess#Security#Cheese
https://t.co/YWBfY0NhHl
@SilvermanJacob iirc you can capture recovery codes, save them in your password manager, and turn off everything else. For someone like you I would recommend doing as much as possible to protect your account
@messycupcakes I think the sensation I have had about it is that it is not a music festival. It's a thing that has music at it. I like music but I don't think I wanna go to the thing
@messycupcakes Gotta disagree with you here MC. At the very beginning of the teasing phase for TLG a lot of their socials left open to interpretation that they were breaking up/the upcoming album might be their last. When the song came out they told the story but before that it was a mystery
@SilvermanJacob I think another poster suggested ensuring your account allow Passkey or Yubikey -- and only those methods -- for signin. Highly recommend this advice. Feel free to inquire if you ever have any questions about securing your stuff
@SilvermanJacob This seems about normal if your account is broadly known / has been seen in credential dumps from other providers. Threat actors take those dumps and then mass-scan services for exposures slowly.
@sama It's a major bummer that you don't give enterprise customers a subdomain option. Makes it very very hard to control traffic through DNS filters and proxies.
@messycupcakes The power converter (plugs into wall, has a USB socket) is solid-state equipment that very rarely breaks or goes bad and is essentially universal (any converter works with any USB cable.) They are everywhere, and if every new device came with one that would hugely increase waste