Après la journée de boulot bien déprimante (quelle joie de se coltiner les documentations insupportables de Microsoft pour gérer le MFA sur #office365admin quand on n'a pas de licence bidule P1) il était indispensable de faire quelque chose de productif. Bon je ne sais pas trop par où commencer maintenant. Ça compte pour #MardiPatisserie @athenavocat ?

We've run a packet capture of the "Admin" app when it is launched, and it sends a GET request to admin.microsoft.com as I would expect, followed by the SSO login to login.microsoft.com, then back to admin.microsoft.com. The traffic is as expected for accessing admin.microsoft.com

The Microsoft 365 Admin app description looks dodgy-as, but all indicators is that it is legitimate.

#infosec #office365 #office365admin #microsoft365 #microsoft365admin

UPDATE: The app appears to be legitimate.

Does anyone know if Microsoft365 updated their "app" today? When logging into the admin center, we got a dodgy notification that the app has been installed. All the writing is in Arabic (I've seen other reports of it being in Russian).

We haven't found any evidence of it being installed in any logs.

The link shown in myapps is seemingly legitimate and goes to the office365 admin portal.

#infosec #office365 #office365admin