Join our Newsletter — 33% off our NHI Course

Entra tenant branding abuse: what IAM teams need to know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Attackers abused Microsoft Entra ID tenant branding to send phishing emails from legitimate Microsoft infrastructure that passed SPF, DKIM, and DMARC, with analysis of 2,000 messages across 250-plus abused tenants showing a scripted burn-and-churn campaign, according to Abnormal AI. The real risk is not spoofing, but trust being encoded into platform-generated identity notifications.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “System Notification Abuse: How Attackers Force Microsoft to Send Phishing Emails”.

By the numbers:

  • Analysis of 2,000 messages across 250-plus abused tenants showed a scripted burn-and-churn campaign.

Key questions

Q: What breaks when identity notifications can be edited by tenant admins?

A: When tenant-controlled fields flow into system notifications, the notification channel stops being a neutral delivery mechanism and becomes part of the attack surface.

Q: Why do SPF, DKIM, and DMARC not stop this kind of phishing?

A: They validate message authenticity signals, but they do not prove the communication is safe or legitimate in context.

Q: What are the signs that identity notification workflows are being abused?

A: Look for tenant-name abuse, callback numbers in verification emails, long scam text inserted into branding fields, and Unicode lookalikes that defeat scanning.

Practitioner guidance

  • Tighten tenant-branding permissions Limit who can edit tenant name and notification-related fields in Microsoft Entra ID, and review whether those fields are allowed to flow into system-generated emails.
  • Replace static allowlists for identity mail Stop treating [email protected] and similar senders as unconditional trust signals, and apply content inspection to identity notifications before delivery.
  • Detect obfuscation in verification traffic Look for homoglyphs, letter-for-digit substitutions, and unusually long tenant strings in account-verification messages, especially when the message contains a callback number.

Bottom line: The core failure is not email spoofing but the abuse of trusted identity workflows to deliver fraudulent content from legitimate infrastructure.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Tenant-controlled identity notifications are now a phishing surface, not just an administration detail. The abuse here is not limited to message styling. It shows that identity platforms can inherit an attacker’s content if tenant-managed fields flow into system templates. That turns branding and verification workflows into governance objects, because the security question becomes who can influence trusted notifications and how that influence is bounded.

A few things that frame the scale:

  • Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.

A question worth separating out:

Q: How should organisations govern allowlisted Microsoft security mail?

A: Treat allowlisted identity mail as a controlled workflow instead of a permanent exception. Validate the content, the enrolment path, and the administrative rights that can shape the message. If trusted sender logic is not paired with content inspection, the allowlist becomes a delivery guarantee for abuse.

👉 Read our full editorial: Microsoft Entra tenant branding abuse turns trust into phishing


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.