Cloud Security · Credential Theft
Blank Entra Logs Can Hide Credential Checks Defenders who wait for a normal successful sign-in can miss account probing in Microsoft Entra ID. Attackers are using spoofed OAuth client IDs to test usernames and passwords through failure codes and blank app fields, not through a clean login event.
Proofpoint says the technique shows up in Entra sign-in logs as an empty or unknown application name, with AADSTS700016 signaling that a username and password pair is correct. It has already appeared in multiple large-scale campaigns across thousands of Microsoft Entra tenants.
That makes log rules tied to named applications or successful sign-ins a weak control for spotting password spraying and user enumeration. The gap is in the telemetry itself: a valid credential can be confirmed without leaving the record defenders expect to see.
4 sources · Jul 18
Timeline Sources Jul 18 Proofpoint
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
OAuth client ID spoofing lets attackers test Entra accounts and stolen passwords without successful sign-ins, leaving application names blank in logs.
original Jul 14 The Hacker News
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
original Jul 13 Infosecurity Magazine
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-07-13
Every edition of this story: Blank Entra Logs Can Hide Credential Checks
Cloud Security · Credential Theft
Blank Entra Logs Can Hide Credential Checks Defenders who wait for a normal successful sign-in can miss account probing in Microsoft Entra ID. Attackers are using spoofed OAuth client IDs to test usernames and passwords through failure codes and blank app fields, not through a clean login event.
Proofpoint says the technique shows up in Entra sign-in logs as an empty or unknown application name, with AADSTS700016 signaling that a username and password pair is correct. It has already appeared in multiple large-scale campaigns across thousands of Microsoft Entra tenants.
That makes log rules tied to named applications or successful sign-ins a weak control for spotting password spraying and user enumeration. The gap is in the telemetry itself: a valid credential can be confirmed without leaving the record defenders expect to see.
4 sources · Jul 18
Timeline Sources Jul 18 Proofpoint
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
OAuth client ID spoofing lets attackers test Entra accounts and stolen passwords without successful sign-ins, leaving application names blank in logs.
original Jul 14 The Hacker News
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
original Jul 13 Infosecurity Magazine
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-07-13
Every edition of this story: Blank Entra Logs Can Hide Credential Checks