Bypass Record
LSASS Credential Dumping × Microsoft Windows Hello for Business
A publicly-reported instance of LSASS Credential Dumping bypassing Microsoft Windows Hello for Business, recorded with its original source. Factual record; no assessment of any specific deployment.
Reported as
abuses Windows Hello for Business (WHFB) keys to authenticate to Microsoft Entra ID without the victim's PIN, biometrics, or password
Mechanism
Attackers with access to an active Windows session export WHFB key material (likely via LSASS or DPAPI) and use it to authenticate to Entra ID services, bypassing the need for PIN or biometric verification. This defeats the passwordless authentication assurance of WHFB.
Detection & mitigation
Monitor for suspicious access to LSASS or DPAPI where WHFB keys are stored, such as unexpected process access or credential export tools. Enforce conditional access policies and investigate anomalous Entra ID authentications lacking MFA or biometric prompts.
This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.