how to detect the AiTM phishing by Microsoft Defender for Cloud Apps

Taro Yamada 26 Reputation points
2022-12-07T11:09:22.273+00:00

Hello,

I found the sentence 'Microsoft Defender for Cloud Apps detects this AiTM phishing' on the bellow document.
https://www.microsoft.com/en-us/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/

So I'm interested to Microsoft Defender for Cloud Apps.
Could you tell me how to detect the AiTM phishing in the following situation?

We have the web page on AWS Amplify.
When users login to the page, they are redirected to auth0.com for authentication.
The username and password are necessary for authentication.
If user enables MFA(mail, SMS, or Push notification), MFA is also necessary.

Thanks.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
{count} vote

Accepted answer
  1. Marilee Turscak-MSFT 34,306 Reputation points Microsoft Employee
    2022-12-14T20:28:19.527+00:00

    As you mentioned, you can connect AWS to Microsoft Defender for Cloud Apps without having Azure as an IdP. Based on my understanding your users will still be protected and the built-in policy templates used to detect AiTM phishing (impossible travel, atypical travel) would be available. To clarify though, you still need to have an Azure account, at least one Global Admin user, and enough licenses to cover protected users in order to use Microsoft Defender for Cloud Apps.

    Reference:
    Prerequisites for using Microsoft Defender for Cloud Apps.

    If you follow the onboarding process, your AWS resources will be monitored in Microsoft Defender for Cloud Apps and you will be able to use the protections detection policies to detect AiTM phishing. I've also reached out to the product team to verify if there are any limitations around your scenario though and will provide their response. Based on my understanding it should work since the AiTM phishing detection is based on those other three built-in detection policies that are included when integrating AWS.

    -

    If the information helped you, please Accept the answer. This will help us and other community members as well.


0 additional answers

Sort by: Most helpful