Skip to content

Does not detect for all gaps in CA #2

@peterke1337

Description

@peterke1337

Tried a quick test of this, it does not seem to be detecting the proper endpoints that are vulnerable.

For example:
My test environment has MFA on all sources except for Desktop Client applications.
The script will tell me all platforms are safe with MFA, however, if i simply login on Outlook desktop with the testcredentials, i will enter without MFA.

I did not continue testing all the other variables since this immediately means it did not detect a major MFA gap.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions