Cybersecurity researchers have uncovered a new attack technique that enables hackers to gather Microsoft Entra user information while avoiding many of the platform’s standard security alerts.
According to cybersecurity firm Proofpoint, attackers are increasingly using spoofed OAuth client IDs to disguise their activities, making it harder for security teams to detect account enumeration and credential validation attempts.
OAuth client IDs are used by Microsoft Entra to identify applications requesting access to user data. By forging these IDs, attackers can attempt to verify usernames and passwords without operating a legitimate or trusted application.
Proofpoint said the technique allows threat actors to determine whether user accounts and passwords are valid without generating successful sign-in events, reducing the likelihood of triggering traditional security monitoring.
The spoofed client IDs also leave the application field blank in Microsoft Entra logs, making it difficult for security teams to identify suspicious activity through application-based monitoring. As a result, compromised credentials may go unnoticed even when account enumeration attempts are detected.
Researchers also found that the method can bypass conditional access policies configured for specific applications, allowing attackers to avoid another key layer of cloud security.
Proofpoint identified two large-scale campaigns using the technique. One campaign, which began in January, employed more than 700,000 spoofed client IDs to target over one million user accounts across nearly 4,000 organizations. A second campaign, first observed in December with another wave in February, was even larger, using approximately 3.7 million spoofed IDs to target more than two million users.
The cybersecurity firm warned that the growing use of spoofed client IDs indicates the technique is gaining popularity among threat actors targeting cloud environments.
To reduce risk, Proofpoint advised organizations to monitor Microsoft Entra logs for sign-in attempts with blank application IDs and to investigate the Entra error code AADSTS700016, which is associated with unrecognized application IDs.

Meet Nandini Shukla, a dedicated branding and marketing professional with over three years of experience in the industry. Known for her result-oriented and hard-working nature, Nandini specializes in enhancing brand aesthetics and formulating effective marketing strategies. Her passion lies in creating content and strategies that are not only visually appealing but also impactful, ensuring that each brand she works with leaves a memorable impression.
At technewsme.com, Nandini combines her keen eye for beauty with her expertise in marketing to offer unique perspectives and transformative solutions. She is committed to helping clients achieve their goals by blending form and function in every strategy she develops. Join her on this journey as she shares insights and tips to elevate your brand in the dynamic world of marketing.