The Legacy Loophole: How Attackers Are Exploiting Entra ID and What to Do About It

A glowing digital chain breaks over a blurred world map, warning symbols and “Research Insights” above—symbolizing a security breach as attackers exploit a legacy loophole for global disruption.

Key takeaways

  • Legacy authentication creates exposure: Protocols like BAV2ROPC can bypass MFA and Conditional Access, enabling silent logins with stolen credentials.
  • Guardz tracked a coordinated campaign: Between March 18 and April 7, 2025, researchers observed systematic attacks across distributed global infrastructure.
  • Attack volume was substantial: More than 9,000 suspicious Exchange login attempts were observed, with a major spike reaching 8,534 attempts on April 5.
  • Exchange and identity systems were primary targets: Over 90% of attacks focused on Exchange Online and Microsoft Authentication Library endpoints.

Between March 18 and April 7, 2025, Guardz Research tracked a targeted campaign exploiting legacy authentication protocols in Microsoft Entra ID. At the center of this operation was BAV2ROPC, a legacy login method that lets attackers sidestep modern defenses like Multi-Factor Authentication (MFA) and Conditional Access.

These attacks were not random. They were systematic, automated, and coordinated across the global infrastructure. The only thing that stopped them was a strong configuration. If your environment still allows legacy authentication, you are a sitting target.

Why Legacy Authentication Still Poses a Risk

Legacy authentication methods, such as BAV2ROPC, SMTP AUTH, POP3, and IMAP4, lack modern security features. These protocols bypass MFA, ignore Conditional Access, and enable silent, non-interactive logins. In short, they create a hidden backdoor into your environment.

Microsoft has deprecated or disabled most of these protocols, but many tenants still rely on them for business continuity or due to outdated systems. That reliance is exactly what attackers are counting on.

What Is BAV2ROPC?

BAV2ROPC stands for “Basic Authentication Version 2, Resource Owner Password Credential.” It was designed to help legacy apps transition to OAuth 2.0 by converting username and password-based logins into token-based access.

Here’s how it works:

  • The app sends a username and password to Entra ID
  • Entra ID issues tokens without user interaction
  • No login screen, no MFA challenge, no alerts

BAV2ROPC is often triggered by outdated mail clients, automated scripts, or stolen credentials, making it a favorite tool in the attacker’s playbook

Attack Campaign Breakdown

The threat actors behind this campaign showed a deep understanding of identity systems. Their attacks were:

  • Coordinated across dozens of unique IPs
  • Automated with credential spraying and brute-force tactics
  • Focused on legacy endpoints that remain exposed in many environments

Still have questions before choosing a plan?
Talk to a real human. No forms. No waiting. No Slack account needed.

No Slack account needed.

Key Findings:

  • Over 9,000 suspicious Exchange login attempts were observed in a short time
  • Attacks originated primarily from Eastern Europe and the Asia-Pacific region
  • Clear evidence of distributed infrastructure and IP rotation

The campaign followed a structured timeline:

  • Initial Probing (March 18–20): Low volume, targeted reconnaissance
  • Sustained Attacks (March 21–April 3): Consistent daily volume with strategic bursts
  • Intensification (April 4–7): Major spike in attempts, peaking at 8,534 on April 5

How the Attacks Worked

The attackers targeted several legacy authentication vectors:

  • OAuth Legacy Flow: 12,221 attempts
  • Password Authentication (Value: 16): 28,150 attempts
  • Basic Authentication (Value: 1): 27,332 attempts
  • Legacy Exchange (Value: 8): 21,080 attempts

More than 90 percent of attacks targeted Exchange Online and the Microsoft Authentication Library. These were not random hits. They were calculated moves to access email, identities, and session tokens.

Admin accounts were a specific focus. One subset received nearly 10,000 attempts from 432 IPs within 8 hours. That level of automation reveals a campaign built to breach and escalate fast.

Read more in the full report here.

Categories:

Frequently Asked Questions

Legacy authentication can expose accounts because older flows may accept username-and-password authentication without invoking modern interactive security controls.

  • Inventory applications and scripts still using basic or legacy authentication.
  • Disable unused protocols such as POP, IMAP, and SMTP AUTH wherever business requirements allow.
  • Treat successful non-interactive logins from unfamiliar infrastructure as high-risk events.
  • Migrate legacy applications to modern OAuth-based authentication before enforcing broader blocks.

Explore our guide to the Top 5 Identity-Related Threats and How to Prevent Them.

Administrative accounts give attackers a faster path from credential compromise to privilege escalation, persistence, and broader tenant access.

  • Separate administrative identities from everyday user accounts.
  • Block legacy authentication for privileged accounts first.
  • Alert on password spraying, repeated failures, and successful logins from new locations or IP ranges.
  • Review privileged-role assignments regularly and remove unnecessary permissions.

For additional guidance on reducing excessive identity privileges, see How Attackers Leverage Over-Permissions.

MSPs should correlate authentication logs with applications, protocols, service accounts, and business owners before enforcing blocks so security improvements do not unexpectedly break critical workflows.

  • Baseline legacy sign-ins over several business cycles before making policy changes.
  • Map each legacy login to its source application, account, and protocol.
  • Prioritize remediation for privileged accounts and internet-facing services.
  • Build exceptions only for documented business dependencies with compensating controls and expiration dates.

For a broader approach to hardening Microsoft environments, see How to Secure Microsoft 365 for MSP Clients.

Guardz can help MSPs surface suspicious identity activity across client environments so abnormal login behavior and potential credential abuse can be investigated more efficiently.

  • Centralize identity-risk visibility across multiple customer tenants.
  • Prioritize abnormal authentication patterns instead of reviewing every failed login manually.
  • Correlate identity signals with broader endpoint, email, and cloud activity.
  • Standardize investigation and remediation workflows across MSP-managed environments.

Guardz supports a more centralized security model that helps MSPs prioritize identity risks and apply repeatable security practices across many SMB tenants.

  • Use unified visibility to reduce time spent switching between client-specific security consoles.
  • Standardize remediation around risky accounts, excessive permissions, and suspicious sign-ins.
  • Correlate identity events with other attack-surface signals to improve triage accuracy.
  • Turn recurring identity findings into measurable security improvements for client reporting.

For more on managing protection from endpoints through identities, see From Endpoints to Identities: Why MSPs Need a User-Centric Approach.

Subscribe to
Our Newsletter.

Abstract image of two overlapping shield shapes, one dark blue and one green, with a soft glowing effect on a light background—perfect for enhancing your single post template with a modern, secure aesthetic.
Abstract image with a large dark blue, semi-circular shape overlapping a bright green, glowing circular shape on a light gray background. Perfect for enhancing your single post template, the green circle appears partially blurred and luminous.

Keep your clients secure.

A stylized, dark blue shield icon with a green gradient glow on the right side, set against a light gray background—ideal for enhancing your single post template design.
A person in a futuristic chair sits at a high-tech control panel, looking out at a starry space scene with planets and mountains. The dashboard glows with colorful buttons and screens, like the perfect single post template for exploring new worlds.

Guardz, Your Cybersecurity
Co-Pilot for MSPs

Demonstrate the value you bring to the table as an MSP and gain visibility into your clients’ external postures.

Holistic Protection.
Hassle-Free.
Cost-Effective.
Slack
Slack
Chat with us No Slack account needed.