
Principal Identity Security Researcher
Microsoft
As organizations move to stronger authentication methods to combat password-related attacks, token theft attacks—which enable attackers to impersonate users even in environments with strong authentication—are on the rise.
Fortunately, Entra ID has built-in protections, such as token protection and continuous access evaluation (CAE), to mitigate attacks such as Adversary-in-the-Middle (AitM) and malware on the endpoint.
This demo-packed session explains how to use those protections, how they work under the hood, what they protect against, how threat actors can leverage them in specific scenarios, and how to detect such abuse.