Microsoft Active Directory Federation Services is one of the most widely deployed authentication systems in enterprise IT. Organisations use it to provide single sign-on across internal and external applications, often as a bridge between on-premises Active Directory and cloud services.
It is also structurally vulnerable to a class of attack that legacy MFA cannot stop.
ADFS enables single sign-on by acting as an identity provider. When a user tries to access an application, ADFS handles the authentication and issues a token that grants access. The application trusts the token. It does not re-verify the user.
This design made sense when enterprise applications lived on the internal network and users logged in from managed devices. It creates a serious problem in modern environments where users access applications from anywhere and attackers have learned to abuse the redirect mechanism at the centre of how ADFS works.
ADFS redirects are not a bug. They are how the protocol works.
When a user tries to access a federated application, the application redirects them to the ADFS endpoint for authentication. After authentication, ADFS redirects them back. The redirect parameters are passed in the URL and accepted at face value.
Attackers have learned to construct requests that look legitimate to ADFS but route victims through attacker-controlled infrastructure before returning them to the real service. The victim sees real Microsoft URLs throughout. The authentication completes normally. The attacker captures the session.
This is not a vulnerability in one product or one campaign. It is a consequence of how redirect-based federation protocols handle trust. Any system built on these assumptions carries the same risk.
At the heart of this exploit is a design flaw in most MFA: it trusts the session flow instead of validating the origin.
Traditional MFA methods — SMS codes, authenticator apps, push prompts — all fail here. Why? Because they never check:
Without those checks, any real-time relay or redirect attack can succeed. This is exactly how groups like Scattered Spider and Octo Tempest have breached insurers, airlines, and global distributors in the past year.
TokenCore™ Wearable and TokenCore™ Portable were engineered specifically to close this class of vulnerability. Here’s how the protection works in practice:
THE RESULT: even if a user clicks a malicious redirect, the phishing kit can’t capture reusable credentials. The login fails silently.
The ADFS redirect exploit underscores a hard truth: attackers don’t need to break into your network — they just need to log in. And as long as authentication methods rely on user judgment or shared secrets, attackers will win.
Microsoft’s redirect endpoints aren’t going away. Neither are phishing kits. Generative AI makes building pixel-perfect login portals trivial in under a minute. Training users to “check the URL carefully” is a losing strategy.
For CISOs, the question is not whether another redirect or relay exploit will emerge — it’s whether your MFA can resist it. If your enterprise is still on SMS, TOTP, push, or even cloud-synced passkeys, you’re already vulnerable.
Token technology changes the equation. With hardware-bound biometrics, cryptographic origin binding, and proximity enforcement, Token eliminates the very attack vectors that redirect exploits depend on. No user decision. No code entry. No chance to relay.
The Microsoft ADFS redirect exploit is just the latest reminder: legacy MFA is obsolete. Attackers aren’t breaking in. They’re logging in — with your users’ help.
Token ensures they can’t.
With TokenCore™ Wearable or TokenCore™ Portable deployed across your workforce:
That’s the standard CISOs should be demanding in 2025. Anything less is wishful thinking.
Read the full coverage of the Microsoft exploit at BleepingComputer. And if you want to see how Token can deadbolt your front door talk to one of our experts.