dafthack/MFASweep

Single Factor Access results not working correctly

EnriqueHernandezL opened this issue · 1 comments

I tested this a few days ago with a Conditional Access Policy that allowed Android access.

The script looks for some hard-coded string in the login response which is not there (anymore).

Looking at the response code instead fixed the issue, as it can tell apart whether MFA gets asked for or not.