{"id":7925,"date":"2024-05-22T09:36:03","date_gmt":"2024-05-22T09:36:03","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=7925"},"modified":"2024-08-22T22:51:37","modified_gmt":"2024-08-22T22:51:37","slug":"single-sign-on-is-insecure-because-stolen-tokens","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens","title":{"rendered":"&#8220;single sign on is insecure because stolen tokens&#8221;"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I sat down with an IT provider today who stated they don&#8217;t use SSO because its insecure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They said its insecure because if the Token gets stolen from the Vendor then the token could be used to authenticate to other providers. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Solutions<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/o365reports.com\/2023\/03\/22\/stop-phishing-attacks-by-token-protection-in-azuread-conditional-access\/\" target=\"_blank\" rel=\"noreferrer noopener\">Conditional Access<\/a>.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft has protection against this using&nbsp;CA only seems to protect employees who are logging in via an Azure AD machine, which all our work computers are.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, there is another Conditional Access feature that can protect you:&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/authentication\/tutorial-risk-based-sspr-mfa\" target=\"_blank\" rel=\"noreferrer noopener\">Risk-based user sign-in protection in Azure Active Directory &#8211; Microsoft Entra | Microsoft Learn<\/a>. With this turned on, a user attempting to connect using the stolen credential from an unusual IP address should trigger an MFA prompt, which the attacker will not be able to complete.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/microsoft-entra-blog\/how-to-break-the-token-theft-cyber-attack-chain\/ba-p\/4062700\">How to break the token theft cyber-attack chain &#8211; Microsoft Community Hub<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/howto-conditional-access-session-lifetime\">https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/howto-conditional-access-session-lifetime<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Token protection ( Preview Only Supports 365 Apps and Services during Preview at the moment ) <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Binds the token to the device so it can&#8217;t be used elsewhere <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/concept-token-protection\">https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/concept-token-protection<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I sat down with an IT provider today who stated they don&#8217;t use SSO because its insecure. They said its insecure because if the Token gets stolen [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-7925","post","type-post","status-publish","format-standard","hentry","category-research"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"I sat down with an IT provider today who stated they don&#039;t use SSO because its insecure. They said its insecure because if the Token gets stolen from the Vendor then the token could be used to authenticate to other providers. Solutions Conditional Access. Microsoft has protection against this using CA only seems to protect employees\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"paris\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Welcome to Pariswells.com |\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\u201csingle sign on is insecure because stolen tokens\u201d | Welcome to Pariswells.com\" \/>\n\t\t<meta property=\"og:description\" content=\"I sat down with an IT provider today who stated they don&#039;t use SSO because its insecure. They said its insecure because if the Token gets stolen from the Vendor then the token could be used to authenticate to other providers. Solutions Conditional Access. Microsoft has protection against this using CA only seems to protect employees\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-05-22T09:36:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-08-22T22:51:37+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:title\" content=\"\u201csingle sign on is insecure because stolen tokens\u201d | Welcome to Pariswells.com\" \/>\n\t\t<meta name=\"twitter:description\" content=\"I sat down with an IT provider today who stated they don&#039;t use SSO because its insecure. They said its insecure because if the Token gets stolen from the Vendor then the token could be used to authenticate to other providers. Solutions Conditional Access. Microsoft has protection against this using CA only seems to protect employees\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/single-sign-on-is-insecure-because-stolen-tokens#article\",\"name\":\"\\u201csingle sign on is insecure because stolen tokens\\u201d | Welcome to Pariswells.com\",\"headline\":\"&#8220;single sign on is insecure because stolen tokens&#8221;\",\"author\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/author\\\/paris#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/#organization\"},\"datePublished\":\"2024-05-22T09:36:03+00:00\",\"dateModified\":\"2024-08-22T22:51:37+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/single-sign-on-is-insecure-because-stolen-tokens#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/single-sign-on-is-insecure-because-stolen-tokens#webpage\"},\"articleSection\":\"Research\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/single-sign-on-is-insecure-because-stolen-tokens#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/pariswells.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/category\\\/research#listItem\",\"name\":\"Research\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/category\\\/research#listItem\",\"position\":2,\"name\":\"Research\",\"item\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/category\\\/research\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/single-sign-on-is-insecure-because-stolen-tokens#listItem\",\"name\":\"&#8220;single sign on is insecure because stolen tokens&#8221;\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/single-sign-on-is-insecure-because-stolen-tokens#listItem\",\"position\":3,\"name\":\"&#8220;single sign on is insecure because stolen tokens&#8221;\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/category\\\/research#listItem\",\"name\":\"Research\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/#organization\",\"name\":\"Welcome to Pariswells.com\",\"url\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/author\\\/paris#author\",\"url\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/author\\\/paris\",\"name\":\"paris\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/single-sign-on-is-insecure-because-stolen-tokens#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/93b8ee3f592ac401167f870452bd82d43de80152cd3524e2853403658ada9984?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"paris\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/single-sign-on-is-insecure-because-stolen-tokens#webpage\",\"url\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/single-sign-on-is-insecure-because-stolen-tokens\",\"name\":\"\\u201csingle sign on is insecure because stolen tokens\\u201d | Welcome to Pariswells.com\",\"description\":\"I sat down with an IT provider today who stated they don't use SSO because its insecure. They said its insecure because if the Token gets stolen from the Vendor then the token could be used to authenticate to other providers. Solutions Conditional Access. Microsoft has protection against this using CA only seems to protect employees\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/research\\\/single-sign-on-is-insecure-because-stolen-tokens#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/author\\\/paris#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/author\\\/paris#author\"},\"datePublished\":\"2024-05-22T09:36:03+00:00\",\"dateModified\":\"2024-08-22T22:51:37+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/\",\"name\":\"Welcome to Pariswells.com\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/pariswells.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\u201csingle sign on is insecure because stolen tokens\u201d | Welcome to Pariswells.com","description":"I sat down with an IT provider today who stated they don't use SSO because its insecure. They said its insecure because if the Token gets stolen from the Vendor then the token could be used to authenticate to other providers. Solutions Conditional Access. Microsoft has protection against this using CA only seems to protect employees","canonical_url":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens#article","name":"\u201csingle sign on is insecure because stolen tokens\u201d | Welcome to Pariswells.com","headline":"&#8220;single sign on is insecure because stolen tokens&#8221;","author":{"@id":"https:\/\/pariswells.com\/blog\/author\/paris#author"},"publisher":{"@id":"https:\/\/pariswells.com\/blog\/#organization"},"datePublished":"2024-05-22T09:36:03+00:00","dateModified":"2024-08-22T22:51:37+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens#webpage"},"isPartOf":{"@id":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens#webpage"},"articleSection":"Research"},{"@type":"BreadcrumbList","@id":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/pariswells.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog\/category\/research#listItem","name":"Research"}},{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog\/category\/research#listItem","position":2,"name":"Research","item":"https:\/\/pariswells.com\/blog\/category\/research","nextItem":{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens#listItem","name":"&#8220;single sign on is insecure because stolen tokens&#8221;"},"previousItem":{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens#listItem","position":3,"name":"&#8220;single sign on is insecure because stolen tokens&#8221;","previousItem":{"@type":"ListItem","@id":"https:\/\/pariswells.com\/blog\/category\/research#listItem","name":"Research"}}]},{"@type":"Organization","@id":"https:\/\/pariswells.com\/blog\/#organization","name":"Welcome to Pariswells.com","url":"https:\/\/pariswells.com\/blog\/"},{"@type":"Person","@id":"https:\/\/pariswells.com\/blog\/author\/paris#author","url":"https:\/\/pariswells.com\/blog\/author\/paris","name":"paris","image":{"@type":"ImageObject","@id":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/93b8ee3f592ac401167f870452bd82d43de80152cd3524e2853403658ada9984?s=96&d=mm&r=g","width":96,"height":96,"caption":"paris"}},{"@type":"WebPage","@id":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens#webpage","url":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens","name":"\u201csingle sign on is insecure because stolen tokens\u201d | Welcome to Pariswells.com","description":"I sat down with an IT provider today who stated they don't use SSO because its insecure. They said its insecure because if the Token gets stolen from the Vendor then the token could be used to authenticate to other providers. Solutions Conditional Access. Microsoft has protection against this using CA only seems to protect employees","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/pariswells.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens#breadcrumblist"},"author":{"@id":"https:\/\/pariswells.com\/blog\/author\/paris#author"},"creator":{"@id":"https:\/\/pariswells.com\/blog\/author\/paris#author"},"datePublished":"2024-05-22T09:36:03+00:00","dateModified":"2024-08-22T22:51:37+00:00"},{"@type":"WebSite","@id":"https:\/\/pariswells.com\/blog\/#website","url":"https:\/\/pariswells.com\/blog\/","name":"Welcome to Pariswells.com","inLanguage":"en-US","publisher":{"@id":"https:\/\/pariswells.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"Welcome to Pariswells.com |","og:type":"article","og:title":"\u201csingle sign on is insecure because stolen tokens\u201d | Welcome to Pariswells.com","og:description":"I sat down with an IT provider today who stated they don't use SSO because its insecure. They said its insecure because if the Token gets stolen from the Vendor then the token could be used to authenticate to other providers. Solutions Conditional Access. Microsoft has protection against this using CA only seems to protect employees","og:url":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens","article:published_time":"2024-05-22T09:36:03+00:00","article:modified_time":"2024-08-22T22:51:37+00:00","twitter:card":"summary","twitter:title":"\u201csingle sign on is insecure because stolen tokens\u201d | Welcome to Pariswells.com","twitter:description":"I sat down with an IT provider today who stated they don't use SSO because its insecure. They said its insecure because if the Token gets stolen from the Vendor then the token could be used to authenticate to other providers. Solutions Conditional Access. Microsoft has protection against this using CA only seems to protect employees"},"aioseo_meta_data":{"post_id":"7925","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","location":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2024-05-22 09:25:33","updated":"2024-08-22 23:04:19","primary_term":null,"seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/pariswells.com\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/pariswells.com\/blog\/category\/research\" title=\"Research\">Research<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t\u201csingle sign on is insecure because stolen tokens\u201d\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/pariswells.com\/blog"},{"label":"Research","link":"https:\/\/pariswells.com\/blog\/category\/research"},{"label":"&#8220;single sign on is insecure because stolen tokens&#8221;","link":"https:\/\/pariswells.com\/blog\/research\/single-sign-on-is-insecure-because-stolen-tokens"}],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7925","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=7925"}],"version-history":[{"count":3,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7925\/revisions"}],"predecessor-version":[{"id":8229,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7925\/revisions\/8229"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=7925"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=7925"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=7925"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}