SMS, voice, and basic push MFA are highly susceptible to session theft. Once authentication completes, cookies and Primary Refresh Tokens become the real target.
Preface
After sign-in, Entra issues session artifacts that maintain authenticated state. Intercepting those artifacts lets attackers clone the user's session on an unauthorized machine.
Problem
Kits such as Tycoon2FA, Rockstar2FA, and Evilginx3 reverse-proxy the Microsoft login page. Credentials and MFA are relayed in real time; the proxy then steals cookies, access tokens, and the PRT. Replay bypasses the full authentication flow, including MFA.
Solution
Align with NIST SP 800-63B AAL3:
- Enforce phishing-resistant MFA: FIDO2 passkeys, passwordless Authenticator, or CBA bound to the legitimate domain.
- Enable Conditional Access Token Protection: Bind tokens to the device TPM so stolen cookies cannot be replayed elsewhere.
- Use Continuous Access Evaluation: Revoke sessions on IP anomalies, password resets, and similar critical signals.
PowerShell: Audit Devices for Cryptographic Bindings
Connect-MgGraph -Scopes "Device.Read.All"
Get-MgDevice -All | Select-Object DisplayName, DeviceId, OperatingSystem, TrustType | Format-Table