OAuth Client ID Spoofing: Attacks on Microsoft Entra without detection signals14. July 2026CybersecurityAttackers can use OAuth client ID spoofing to enumerate Microsoft Entra user accounts and validate credentials without classic sign-in attempts being logged. Share on: