Chrome Web Store Verified

Microsoft Single Sign On

by [email protected] · 36.0M users · 2.2 rating
3d23e9c1-171d-5c64-a82d-d4201f4e6e28 | v1.0.11
0/ 100
MINIMAL risk
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
10 months ago
Version
v1.0.11
Artifact
SHA256 AC3…24A
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Low

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

89
Noisy-finding weight
x1.00
Publisher domain
microsoft.com
Trusted match
Store verification signal
Limited signal
Limited
Extension portfolio
653
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category typosquatting; evidence quality moderate.

Microsoft Single Sign On is marketed as a tool that enables users to sign in to supported websites with a Microsoft work or school account on Windows and macOS platforms. The extension’s manifest.json contains the permission 'nativemessaging' (MANIFEST-SENSITIVE-PERM-NATIVEMESSAGING), a capability that can expose native host communication. Three high‑severity YARA matches are recorded in unknown_file: two entries are titled YARA--postinstall_network_communication and one is titled YARA--postinstall_crypto_operations. These signatures trigger on post‑install network activity and cryptographic operations, respectively. The developer field lists the identifier [email protected], which does not correspond to any publicly documented Microsoft store publisher profile. No IoC findings such as suspicious domains, proxyware behavior, or credential‑theft patterns appear in the analysis. The extension does not contain obfuscation beyond standard bundling, nor does it exhibit typosquatting beyond its name.

A skeptic might argue that the YARA signatures are generic postinstall rules that frequently fire on legitimate extensions and that the native messaging permission is commonly used for legitimate debugging, therefore the findings are harmless. However, the presence of three distinct high‑severity signatures, combined with an anonymous developer name and an extension title that directly mimics Microsoft’s single‑sign‑on functionality, creates a context where benign intent is not evident. Moreover, the extension’s high user count amplifies any potential impact if the permissions were abused. The description provides no concrete service details and relies on vague language about "supported websites," which further weakens the claim of legitimacy. The YARA rule titles belong to a known set that is often associated with malicious extensions seeking to exfiltrate data or perform cryptominer activity after installation. The combination of network‑related and crypto‑related signatures in the same file is atypical for benign utilities.

The strongest counterargument — that the signatures are non‑specific — does not fully explain why the extension would request a sensitive native messaging permission without any accompanying benign use case. Additionally, the extension’s name directly copies Microsoft’s branding, a classic tactic used in typosquatting to gain trust. While the extension may be an earnest attempt to provide an SSO helper, the evidence package does not demonstrate a clear, legitimate purpose. Instead, it exhibits multiple red‑flag patterns that require further investigation. Given the ambiguous nature of the findings, the appropriate classification is needs_follow_up, indicating that additional runtime observation or a deeper code review is required before a final verdict can be issued.

Key Reasons

  • Generic postinstall YARA signatures match common network and crypto patterns
  • MANIFEST-SENSITIVE-PERM-NATIVEMESSAGING permission declared
  • High user count creates amplification risk
  • Extension name mimics Microsoft SSO functionality
  • No specific malicious payload beyond generic signatures

False Positive Considerations

  • generic postinstall YARA rule matches
  • high user count
  • native messaging permission flagged
  • extension name mimics Microsoft SSO functionality

Reviewed 2026-05-23; recommended action: reanalyze; model confidence 66%.

About This Extension

Use this extension to sign in to supported websites with Microsoft work or school accounts on Windows (10 and later versions) or macOS (11 and later versions). If you have a Microsoft Entra ID on your Windows or macOS computer, this extension enables improved Single Sign On for supported websites. You may still see additional authentication prompts like multi-factor verification depending on the access requirements for various applications, resources, and organizations. This extension is required for certain device-based conditional access policies for Microsoft Entra ID. https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-conditions#supported-browsers For macOS, this extension requires the device to be managed and requires the additional installation of Company Portal: https://learn.microsoft.com/en-us/mem/intune/user-help/enroll-your-device-in-intune-macos-cp Note: If you are experiencing difficulties with signing in or accessing resources, it could be related to your organization’s device policies. Please submit a support ticket directly to Microsoft through your tenant’s subscription. The developer email address for the extension is not an avenue for customer support.

Frequently Asked Questions