Mollema found that low-privilege processes in a compromised Windows session can use the Windows Hello for Business key without a fresh PIN or biometric prompt, enabling FIDO2 authentication against Entra ID.
Mollema found that low-privilege processes in a compromised Windows session can use the Windows Hello for Business key without a fresh PIN or biometric prompt, enabling FIDO2 authentication against Entra ID.