THREATOPS
THREAT OPSThreat News › WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blocking

WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blocking

medvaronis_blogPublished 2026-08-12

<p>A legacy Entra ID endpoint kept alive for Office 2013 clients lets attackers spray passwords past Smart Lockout, confirm valid credentials on MFA-protected accounts, and leave only partial logs behind.</p> <p>In 2018, Microsoft introduced <a href="https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-smart-lockout">Smart Lockout</a> into Azure AD, now Entra ID, to make

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.varonis.com/blog/ws-trust-autologon-endpoint