Joonas Westlin 8/24/2019

Cross-tenant token attacks are now harder in Azure AD

Read Original

The article details a security improvement in Azure AD that makes cross-tenant token attacks harder. Previously, an app from one tenant could acquire an access token for an API in another tenant, potentially leading to unauthorized access if permissions weren't validated. Now, both v1 and v2 endpoints block token acquisition unless a service principal for the app exists in the target tenant, though the author emphasizes that APIs must still check token permissions.

Cross-tenant token attacks are now harder in Azure AD

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week