Researchers have linked ExfilSquad breach claims to misconfigured Microsoft Power Pages portals that reportedly exposed Dynamics 365 data through public access. The incident highlights a critical SaaS security lesson: organizations do not need malware or a zero-day to suffer data exposure when configuration, access governance, and monitoring controls fail.
A data-extortion group called ExfilSquad has drawn attention after researchers corroborated several of its breach claims and identified misconfigured Microsoft Power Pages portals exposing Dynamics 365/Dataverse data as the leading theory for how at least some of the data was obtained. The incident demonstrates an increasingly important enterprise security reality: attackers do not always need to compromise software when organizations accidentally leave the door open.
The group claimed data theft from organizations across government, education, aviation, insurance, technology, and other sectors. Reported targets included the City of Atlanta, Allstate, Frontier Airlines, Microsoft, and the U.K. Department for Education.
Earlier threat-intelligence reporting treated many of the group’s initial claims as unverified. More recent reporting, however, has connected ExfilSquad activity with poorly secured Microsoft Power Pages environments.
The distinction matters. Researchers have not tied this activity to ransomware deployment or a conventional software exploit. Instead, the reported access path points toward a SaaS security and configuration-governance problem.
How exposed Power Pages can put Dynamics 365 data at risk
Microsoft Power Pages allows organizations to build external-facing business websites that interact with enterprise data and workflows. That functionality also means administrators must carefully control what anonymous and authenticated visitors can access.
In the reported ExfilSquad incidents, researchers linked exposed information to Power Pages portals that apparently permitted public read access to Microsoft Dynamics 365 data.
That changes the threat model considerably. An attacker may not need to bypass authentication, deploy malware, or exploit a vulnerability if a public-facing application already exposes backend records.
For enterprises, three controls deserve particular scrutiny:
Anonymous access: Determine exactly what unauthenticated visitors can query or view.
Permissions: Apply least privilege to tables, records, roles, and administrative functions.
Configuration monitoring: Regularly review public portals for permission changes and configuration drift.
A seemingly minor access-control mistake can therefore escalate into a SaaS data breach, especially when internet-facing portals connect directly to repositories containing customer, employee, student, or operational information.
Featured Resource
Cybersecurity kit
Get essential cybersecurity resources, best practices, and strategies to strengthen enterprise security.
The incident also shows why SaaS configuration cannot remain isolated from identity governance.
Organizations should tightly restrict who can administer public-facing portals and periodically review privileged access. Administrative privileges that remain active after role changes, unnecessary permissions, or unmanaged administrator endpoints can increase the likelihood and impact of configuration mistakes.
Enterprises should combine least privilege with periodic access reviews, strong authentication, device trust, and continuous monitoring. The objective is not simply to authenticate an administrator. Security teams must also establish whether that user should retain administrative privileges and whether the device accessing the management environment meets organizational security requirements.
How Hexnode strengthens the endpoint-to-SaaS access layer
Hexnode does not configure Microsoft Power Pages table permissions or anonymous access. Instead, Hexnode UEM helps secure the managed administrator endpoints used to access cloud applications by supplying device compliance information to Microsoft Entra ID. Entra Conditional Access can then use that compliance status when deciding whether a supported managed device can access protected organizational resources.
Hexnode UEM can evaluate devices against compliance criteria such as encryption, password requirements, required or blocklisted applications, management status, and jailbreak status. For supported Android, iOS/iPadOS, and macOS devices, Hexnode can report this compliance state to Microsoft Entra ID. Administrators can then configure Entra Conditional Access to require a compliant device before granting access to selected resources.
This creates a clear division of responsibility. Power Pages administrators must correctly configure portal permissions and anonymous access, while Hexnode UEM and Microsoft Entra ID can help restrict administrative access to managed devices that meet organizational compliance requirements. Access decisions themselves are enforced by the identity provider.
Hexnode XDR adds endpoint threat detection and response for Windows administrator endpoints. Its agent continuously monitors endpoint telemetry, including process execution, file activity, network behavior, and system changes. This visibility can help security teams identify malware or infostealer activity that could compromise credentials or session data on a device used to administer SaaS environments.
These controls complement rather than replace Power Pages security. Organizations must secure portal permissions within Microsoft’s platform while using endpoint compliance, Conditional Access, and endpoint threat detection to protect the devices and access paths used by administrators.
FAQs
What is ExfilSquad?
ExfilSquad is a data-extortion group that has claimed attacks against organizations across multiple sectors. Recent reporting has associated some of its activity with exposed Microsoft Power Pages environments rather than traditional ransomware deployment.
Is a SaaS misconfiguration considered a software vulnerability?
Not necessarily. A vulnerability generally involves a weakness in software that an attacker can exploit. A misconfiguration occurs when legitimate functionality or permissions are configured insecurely, such as granting unintended public access to sensitive information.
How can organizations reduce Power Pages data-exposure risks?
Organizations should address SaaS and endpoint risks separately. Within Power Pages and Dynamics 365, administrators should restrict anonymous read access, validate table permissions and portal roles, and regularly review configurations. For administrative access, Hexnode UEM can provide supported device compliance information to Microsoft Entra ID, where Conditional Access policies can require compliant devices before granting access to protected resources. Hexnode XDR can separately help detect and respond to endpoint threats on Windows administrator devices.
Conclusion
The ExfilSquad story reinforces a simple lesson: a breach does not require sophisticated malware. Misconfigured public access can expose SaaS data even when the underlying software functions as intended.
Enterprises therefore need two distinct layers of defense. At the SaaS layer, organizations should restrict anonymous access, review Power Pages and Dynamics 365 permissions, and monitor configuration changes. At the identity and endpoint layer, Hexnode UEM can supply device compliance information to Microsoft Entra ID for Conditional Access decisions, while Hexnode XDR can help detect and respond to threats affecting Windows administrator endpoints.
Keeping these responsibilities separate makes the security model clearer: secure the SaaS configuration itself, then secure the identities and endpoints used to administer it.
Reduce Cloud Data Exposure
Strengthen endpoint security, enforce trusted access, and detect data exfiltration risks with Hexnode UEM and XDR.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.