Publications

Fill 4

ERNW White Paper 80

Token Theft in Microsoft Entra ID - An Analysis of Controls

Cloud identity attacks are shifting from password-based methods to token-based techniques, such as token theft, AiTM attacks, device code phishing, and ConsentFix, that bypass multi-factor authentication. This paper evaluates Microsoft Entra ID’s defense-in-depth strategy against token theft, focusing on Continuous Access Evaluation (CAE), Token Protection, and OAuth 2.0 compliance. Empirical testing reveals that CAE is supported by only 33 of 740 analyzed first-party resource providers, with revocation times varying widely across services (10 seconds for SharePoint/Teams to 5 minutes for Exchange). The study also shows that Token Protection’s default configuration can be partially bypassed via User-Agent manipulation or web client use. Additional gaps against current OAuth 2.0 best practices are identified, including reliance on proprietary mechanisms (PRT, FOCI, BroCI), coarse-grained scopes, limited BFF adoption, continued support for deprecated grant types, and the absence of refresh token rotation for public clients.



Newsletter sign up

Get the latest news about technical topics within the IT-Security Community and a lot of special insights. Sign up now for our Newsletter at ernw.de:


Talks and Conferences arround the world


February 03, 2019

Some Notes on the IPv6 Properties of the Wireless Network @ Cisco Live Europe

Some years ago Christopher wrote two posts (2016, 2015) about the  IPv6-related characteristics of the WiFi network at Cisco Live Europe. To somewhat continue this tradition and for mere technical interest I had a look at some properties of this year’s setting.

January 29, 2019

TelcoSecDay 2019 – First talks preview

This year we had some excellent submissions for TelcoSecDay.  Here are the first four confirmed speakers who are going to talk about the below mentioned topics:

January 28, 2019

2019 – Year Of The Blue Dog…

Back from Holidays, you started the year well motivated to make the world a safer place. However, sitting at your desk today  you realize nothing really changed since last year, and you are surfing the web, feeling a bit blue, trying to avoid that pile of emails waiting for you and wondering how you could […]

January 23, 2019

#TR19 Active Directory Security Track

As some of you might recall we’ve introduced a dedicated “Active Directory Security Track” at last year’s Troopers. For Troopers19 we’ve expanded it to two days (as the SAP Security Track was discontinued), and in the following I’ll provide a list of talks in the track.

January 16, 2019

TROOPERS19 Training Teaser: Hacking mobile applications

“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process our bank transactions, handle our private data and set us up on romantic dates. However, few of us care to wonder,”How (in)secure can these apps be?” Well… at Troopers 19, you can learn how to answer this question yourself! In […]

ERNW Research ERNW Research articles on our company blog