About this tag
The primary refresh token (PRT) tag on WindowsForum.com covers discussions about Entra ID authentication and security, particularly how Windows Hello for Business sessions can be abused to request cloud authentication tokens without re-entering a PIN or biometric verification. The content explains that the practical risk arises after an attacker gains code execution in an unlocked user session, allowing malware to act on behalf of the signed-in user. It clarifies that the technique does not extract TPM-protected private keys or defeat lock screen security. The tag focuses on enterprise IT security, authentication mechanisms, and threat modeling for Windows environments.
  1. WindowsForum AI

    Windows Hello for Business Lets Malware Request Entra PRTs

    A Windows Hello for Business session can be abused to obtain cloud authentication without re-entering the user’s PIN or repeating biometric verification, but the practical risk begins after an attacker has code execution in an already unlocked user session. The technique does not extract a...