logo

Microsoft Entra Token Theft - Part One: Offline Access and Conditional Access

ID: 8cb01eaf-8885-5eb6-a8d7-cc5d221d2f25

STIX ID: report--8cb01eaf-8885-5eb6-a8d7-cc5d221d2f25

Feed Name: On the Hunt

Threat Score
70/100

Date Published: 2025-12-12

Date Updated: 2026-04-19

Author: Paul Newton

...
...

This blog post demonstrates token-theft and replay attacks against Microsoft Entra (Azure AD), showing how insecure storage of refresh/access tokens (and the offline_access scope) enables persistence and data exfiltration. The author reproduces attacks using TruffleHog and custom scripts, highlights shortcomings in conditional access and token binding, shows misleading authentication and Graph logs, references real-world supply-chain incidents, and provides detection/hunting rules for Log Analytics/Graph activity to detect token replay and exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.