Exploit Library
File
Privacy-Preserving_Potential_HTTP2.pdf · 1.2 MB · click to show
Privacy-Preserving_Potential_HTTP2.pdf · 1.2 MB · click to show
File
Token_Theft_MS_EntraID.pdf · 3.6 MB · click to show
Token_Theft_MS_EntraID.pdf · 3.6 MB · click to show
#Analytics
#Cloud_Security
ERNW White Paper 80:
"Token Theft in Microsoft Entra ID - An Analysis of Controls", Ver.1.0, Aug. 2026.
// Cloud identity attacks are shifting from password-based methods to token-based techniques, such as token theft, AiTM attacks, device code phishing, and ConsentFix, that bypass multi-factor authentication. This paper evaluates MS Entra ID’s defense-in-depth strategy against token theft, focusing on CAE, Token Protection, and OAuth 2.0 compliance. Additional gaps against current OAuth 2.0 best practices are identified, including reliance on proprietary mechanisms (PRT, FOCI, BroCI), coarse-grained scopes, limited BFF adoption, continued support for deprecated grant types, and the absence of refresh token rotation for public clients
11 · 352 ·