Deep dive Federated Identity Credentials in Microsoft Entra

By 27 min read

Topics: Azure, Entra ID, Security

MITRE ATT&CK: T1528, T1098.001

Deep dive Federated Identity Credentials in Microsoft Entra

User-assigned managed identities are designed to eliminate credential management. But the same trust model that makes them secure, federated identity credentials can be weaponised to extract bearer tokens for any resource the identity can access. This article explains a technique that injects a temp