Get remediation support for nOAuth
In June 2023, Descope disclosed an authentication implementation flaw that can affect Microsoft Azure AD multi-tenant OAuth applications. If you believe your app is impacted, fill in the form and our security team will reach out to you.
nOAuth demo video
Watch this 3-min demo video to see how nOAuth can be exploited to perform account takeover on any app that incorrectly implements "Log in with Microsoft".
![nOAuth video thumbnail](/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2Fxqb1f63q68s1%2FlbMEDVazJzMTonwAG3Clt%2Fa583a273d15b3af9ebb5aa12c79ac446%2FnOAuth_video_thumbnail.png&w=3840&q=75)
More resources
Microsoft advisory
Microsoft has introduced two new claims that developers can use to redact emails that come from non-verified domains.
Microsoft guidance
Following Descope’s disclosure, Microsoft has published a dedicated page on claims validation with strong developer guidance.
Descope guidance
If you are a Descope customer – or are curious about how Descope can help you fix this configuration issue quickly – check out our developer blog below.