Home / Companies / Prowler / Blog / Post Details
Content Deep Dive

Adapting to Microsoft's MFA Enforcement: Prowler's New Certificate-Based M365 Authentication

Blog post from Prowler

Post Details
Company
Date Published
Author
Hugo P.Brito
Word Count
656
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

Prowler, a cloud security tool, has adapted to Microsoft's enforcement of multi-factor authentication (MFA) for Microsoft 365 by introducing a new certificate-based authentication method. Originally, Prowler supported Microsoft 365 through Service Principal authentication, later expanding to include username and password methods via PowerShell modules. However, with Microsoft's policy change blocking non-interactive access for user credential sign-ins, Prowler deprecated the older method and enhanced its Service Principal authentication to eliminate the need for user credentials. The new version 5.13 now features certificate-based authentication as a secure alternative, which involves creating a self-signed certificate, uploading it to Microsoft Entra, and providing an encoded credential in Prowler Cloud to maintain full Microsoft 365 functionality, thereby enhancing security against account compromise attempts.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 2 1,423 250 85 +59%
MCP 2 4,861 352 133 +57%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.