Is Microsoft Single Sign On safe?
Microsoft Single Sign On relays postMessage calls from any HTTPS page to a native Windows Web Authentication Manager (WAM) bridge via a hardcoded channel UUID.
The extension's content script registers a message listener on all HTTPS pages that forwards caller-supplied payloads to the native host com.microsoft.browsercore, which handles silent Entra ID / Azure AD authentication. The only inbound gate is a hardcoded channel UUID that is shipped in the extension bundle and readable by any page script, meaning any JavaScript on any HTTPS page can drive the native host with attacker-controlled method names and parameters. The background script injects the sender origin before forwarding, but does not otherwise restrict which pages or methods may invoke the bridge.
Who publishes itMicrosoft - 1 other listing from the same operator, none carrying a finding
Microsoft - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 2.0M+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 1.0.11. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Where it sends data
Destinations our analysis observed Microsoft Single Sign On contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.microsoft.browsercore
Microsoft Single Sign On sends data to com.microsoft.browsercore. No other extension we have analysed sends data here.