A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Suspected Compromise Involving Microsoft Authenticator and Entra Activity
Reporting a suspected compromise involving:
- Microsoft Authenticator
- Silent appearance of Microsoft Entra ID-linked behavior
- Unauthorized device trust and token issuance across iOS and Windows platforms
Critically, there was no explicit registration for Microsoft Entra ID, nor was the device enrolled in Intune, Azure AD, or any enterprise federation. The only account in use was a personal Outlook account with Microsoft Authenticator utilized as a 2FA tool.
Key Indicators of Unauthorized Activity
1. Silent App Reinstalls & Token Activity
- Authenticator, AzureAuth, LinkToWindows, and other Microsoft apps reappeared after device resets or restorations.
- Apple system logs (xp_amp_app_usage_dnu) show
installType: priorfor these apps, indicating they were not manually reinstalled. - All events are tied to a single
usageClientId:
CA82B87B-CABE-42BB-B5C6-890D9736B87C
2. Entra-Like Behavior Despite No Entra Account
- Sign-ins via Microsoft Authenticator have triggered cross-device session binding, even though:
- No Intune profile was installed
- No organizational account was used
- No registration for Microsoft Entra
- Both Windows and iPhone showed persistent trust sessions (Entra or hybrid-compliant device behavior), seemingly linked via token sync or silent SSO.
- No registration for Microsoft Entra
- No organizational account was used
- No Intune profile was installed
3. Suspicious Background Identity & UI Modeling
- iOS logs show concurrent activity by:
-
MTLCompilerService (×5 spawns)— linked to UI rendering/fingerprinting-
pairedunlockd,DayStreamProcessorService,HistoricalAnalyzerService- All occurring during or around silent Authenticator reinstallation
- SQLite and background telemetry daemons (e.g.,
duetexpertd,contextstored) show disk I/O without user activity
- SQLite and background telemetry daemons (e.g.,
- All occurring during or around silent Authenticator reinstallation
-
-
Security Concerns
- Unauthorized enrollment of personal identity in Entra-like token infrastructure
- Silent reappearance of trusted apps (Authenticator, AzureAuth) across resets
- Possible cross-device SSO propagation, violating user expectations
- Potential abuse of App Store or Apple background services to pre-provision identity context
Requested Microsoft Actions
- Audit Microsoft Authenticator activity and device binding logs for:
- Silent or background Entra association
- Impersonated device provisioning
- Cross-tenant federation
- Purge and revoke any device identity or token trust associated with:
- iOS device (iPhone running version 18.5)
- Windows machine using the same Outlook login
- Impersonated device provisioning
- Confirm whether silent federation, token replay, or Authenticator auto-configuration is possible in cases where:
- Only a personal Outlook account is used
- User did not register for Microsoft Entra
Microsoft Security | Microsoft Authenticator
1 answer
Sort by: Oldest
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more