Cloud identity attacks are shifting from password-based methods to token-based techniques, such as token theft, AiTM attacks, device code phishing, and ConsentFix, that bypass multi-factor authentication. This paper evaluates Microsoft Entra ID’s defense-in-depth strategy against token theft, focusing on Continuous Access Evaluation (CAE), Token Protection, and OAuth 2.0 compliance. Empirical testing reveals that CAE is supported by only 33 of 740 analyzed first-party resource providers, with revocation times varying widely across services (10 seconds for SharePoint/Teams to 5 minutes for Exchange). The study also shows that Token Protection’s default configuration can be partially bypassed via User-Agent manipulation or web client use. Additional gaps against current OAuth 2.0 best practices are identified, including reliance on proprietary mechanisms (PRT, FOCI, BroCI), coarse-grained scopes, limited BFF adoption, continued support for deprecated grant types, and the absence of refresh token rotation for public clients.
Get the latest news about technical topics within the IT-Security Community and a lot of special insights. Sign up now for our Newsletter at ernw.de:
Some years ago Christopher wrote two posts (2016, 2015) about the IPv6-related characteristics of the WiFi network at Cisco Live Europe. To somewhat continue this tradition and for mere technical interest I had a look at some properties of this year’s setting.
This year we had some excellent submissions for TelcoSecDay. Here are the first four confirmed speakers who are going to talk about the below mentioned topics:
Back from Holidays, you started the year well motivated to make the world a safer place. However, sitting at your desk today you realize nothing really changed since last year, and you are surfing the web, feeling a bit blue, trying to avoid that pile of emails waiting for you and wondering how you could […]
As some of you might recall we’ve introduced a dedicated “Active Directory Security Track” at last year’s Troopers. For Troopers19 we’ve expanded it to two days (as the SAP Security Track was discontinued), and in the following I’ll provide a list of talks in the track.
“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process our bank transactions, handle our private data and set us up on romantic dates. However, few of us care to wonder,”How (in)secure can these apps be?” Well… at Troopers 19, you can learn how to answer this question yourself! In […]