Windows Hello for Business is designed to make sign-ins easier and more secure by replacing passwords with keys tied to a specific device. But recent security research shows that if malware is already running on a signed-in Windows session, it can silently use those keys to access Microsoft Entra ID (formerly Azure AD) and establish longer-term, persistent access to your cloud environment.
For small businesses that rely on Microsoft 365 and Entra ID, this is more than a technical curiosity. It’s a practical reminder that “passwordless” does not mean “risk-free,” and that endpoint security, identity protection, and conditional access all need to work together.
Key Takeaways
- Windows Hello for Business keys can be abused by malware running in an already signed-in Windows session.
- Attackers can use those keys to authenticate to Microsoft Entra ID without the user seeing prompts.
- Once in Entra ID, attackers may register new devices, obtain a Primary Refresh Token (PRT), and add additional authentication methods.
- This can lead to long-term cloud access even if the original device is later cleaned or the user changes their password.
- Small businesses should harden endpoints, tighten identity and device policies, and monitor for suspicious device registrations and MFA changes.
What the Research Shows
Entra ID researcher Dirk-jan Mollema demonstrated that malware operating under a signed-in user session can:
- Access the user’s Windows Hello for Business key material on that device.
- Silently use the key to authenticate to Microsoft Entra ID on behalf of the user.
- Interact with Entra ID as if it were the user, including performing device registration and token enrollment steps.
The core issue is not that Windows Hello for Business is “broken,” but that once malware has control inside a user session, it can leverage legitimate credentials and keys to move deeper into your environment. Instead of stealing passwords, it just uses the strong authentication method you already trust.
Why Windows Hello for Business Matters
Windows Hello for Business is widely adopted because it:
- Replaces passwords with cryptographic keys.
- Ties those keys to specific devices, protected by hardware and/or TPM.
- Supports biometric sign-in (face or fingerprint) and PINs.
- Integrates tightly with Microsoft Entra ID and on-premises Active Directory.
In normal use, this significantly improves security over passwords alone. Attackers cannot simply reuse a stolen password from a phishing email. However, when malware is already running under the user’s context, the threat shifts from theft of credentials to abuse of session-bound keys and tokens.
How Malware Can Turn Hello Keys into Persistent Cloud Access
1. Starting Point: Compromised Windows Session
The attack starts the same way many compromises do:
- The user opens a malicious attachment, link, or installer.
- Malware runs with the user’s permissions in their active Windows session.
- The user is already signed in with Windows Hello for Business to Entra ID-backed services.
At this point, the attacker doesn’t need the user’s password or PIN. They just need to operate inside that trusted session.
2. Silent Authentication to Entra ID
From within the active session, the malware can access the APIs and system components that use Windows Hello for Business keys for authentication. Since the device and user are already trusted, the malware can:
- Request authentication to Microsoft Entra ID endpoints.
- Use the Windows Hello key to complete the authentication behind the scenes.
- Avoid triggering obvious prompts that would alert the user.
The result: Entra ID sees a normal, legitimate sign-in from a known device with a valid key, even though it was driven by malware.
3. Device Registration and PRT Acquisition
Once authenticated, the attacker’s next goal is persistence. The research shows that the attacker can:
- Register a new device in Entra ID that the attacker controls, if tenant policies allow self-service registration.
- Obtain a Primary Refresh Token (PRT), which is a long-lived token that enables ongoing access to cloud resources without needing to re-authenticate frequently.
With a PRT tied to an attacker-controlled device, the attacker can:
- Access Microsoft 365 apps and other Entra ID–protected services as the user.
- Survive password resets, because the token and device trust may still be valid.
- Keep connecting from outside your network with what appears to be a legitimate, registered device.
4. Adding New Authentication Methods
If tenant policies are too permissive, the attacker may also be able to:
- Add alternative authentication methods (for example, a new authenticator app or phone number).
- Enroll additional factors that allow login even if the user’s original Hello key or device is revoked.
From a defender’s perspective, this turns a one-time malware infection into a long-term identity compromise that can outlast any cleanup on the original device.
What This Means for Small Businesses
For smaller organizations, this research highlights a few practical realities:
- Endpoint security still matters. Strong identity tools can be undermined if malware is allowed to run freely on user devices.
- Identity and device governance are critical. Self-service device registration and weak controls around authentication methods can give attackers room to escalate.
- Monitoring cannot stop at sign-in success. You have to watch what successfully authenticated sessions do: device registrations, MFA changes, unusual token usage, and more.
“Passwordless” setups are not a reason to relax. They shift your risk from password theft to signed-in-session abuse and identity persistence.
Practical Steps to Reduce Risk
1. Harden Your Windows Endpoints
- Use reputable endpoint protection and EDR tools on all business devices.
- Keep Windows, browsers, and key software up to date with patches.
- Limit local admin rights so that malware has fewer paths to escalate.
- Enforce application control where possible to reduce arbitrary executable use.
The less freedom malware has on a signed-in device, the harder it is to abuse Windows Hello keys and identity tokens.
2. Tighten Entra ID Conditional Access and Device Policies
- Review which users are allowed to register devices and from where.
- Require compliant or hybrid-joined devices for critical cloud apps where appropriate.
- Use conditional access to limit access from unknown locations or impossible travel patterns.
- Consider stricter policies for administrators and high-risk accounts.
By reducing how casually devices can be registered and trusted, you make it harder for attackers to convert a single compromised session into a long-lived foothold.
3. Lock Down Authentication Method Changes
- Require strong verification for adding or changing MFA and sign-in methods.
- Limit self-service changes for high-privilege accounts.
- Monitor for sudden additions of new authenticators, phone numbers, or FIDO devices.
Attackers rely on silently adding their own authentication methods to survive user-initiated changes. Make that as visible and restricted as possible.
4. Monitor for Suspicious Identity Activity
- Use Entra ID sign-in logs and audit logs to detect unusual device registrations.
- Watch for PRT usage from unexpected IP ranges or new regions.
- Set up alerts for risky sign-ins and unfamiliar sign-in properties.
- Periodically review device objects and disable or delete stale or suspicious entries.
Even basic monitoring can help you spot when an account or device starts behaving in ways that don’t match the user’s normal patterns.
5. Educate Users About Endpoint and Identity Risks
- Explain that “passwordless” logins still require safe browsing and email habits.
- Train users to report unexpected prompts, device registration notifications, or authenticator changes.
- Reinforce that approving unknown sign-in attempts in an authenticator app is never okay, even if the notification looks routine.
Human awareness remains a critical part of your defense, especially in small environments without dedicated security teams.
Conclusion: Strong Identity Needs Strong Endpoints
The abuse of Windows Hello for Business keys by malware is a reminder that identity security and endpoint security are tightly linked. Malware inside a trusted Windows session can leverage the very tools that are meant to protect you, using them to authenticate to Microsoft Entra ID, register devices, obtain PRTs, and add additional authentication methods for long-term persistence.
For small businesses, the path forward is not to abandon modern identity tools but to pair them with:
- Hardened and monitored endpoints
- Carefully designed Entra ID and device policies
- Controlled authentication method changes
- Ongoing monitoring and user education
By treating identity and device trust as a single, connected system, you reduce the chances that a one-time malware incident turns into a long-term compromise of your cloud environment.
If you’re working to secure your small business across identity, devices, and the cloud, Izende Studio Web can help you align your applications and infrastructure with practical, modern security practices. Learn more at https://izendestudioweb.com/services/.
