How to Use Token Protection and Compliant-Device Policies Against Token Theft
MFA-bypass phishing kits steal tokens rather than passwords. Two Entra ID controls make stolen tokens much less useful: token protection and compliant-device requirements. Here is how to deploy them.
Control 1: Require compliant devices
If Microsoft 365 access requires a device enrolled and compliant in Intune, a token stolen and replayed from an attacker's computer fails the device check.
- Enroll corporate Windows, macOS, iOS and Android devices in Intune with compliance policies.
- Create a Conditional Access policy for Office 365 (and other sensitive apps) requiring Require device to be marked as compliant (or hybrid joined).
- For personal devices, allow browser-only access with app-enforced restrictions or app protection policies for mobile apps.
- Pilot, then enforce.
Control 2: Token protection
Token protection binds sign-in session tokens to the device they were issued to.
- Review supported platforms, clients and resources (coverage has expanded over time for Windows, and for Exchange Online, SharePoint Online and Teams with supported apps).
- Create a Conditional Access policy with the session control Require token protection for sign-in sessions for a pilot group.
- Use report-only mode to identify unsupported clients.
- Expand to administrators and high-risk users first.
Control 3: Phishing-resistant MFA
Require passkeys or FIDO2 for high-risk users. These can't be phished through proxy sites.
Supporting controls
- Block device code flow.
- Continuous Access Evaluation for fast revocation.
- Identity Protection risk-based policies.
- Short sign-in frequency for sensitive apps on unmanaged devices.
Verify
Test in a lab: replay a session token from a pilot user on a different, unmanaged device. Access to protected resources should be denied.
Sources
- Kali365 and the FBI Warning (May 2026): MFA-Bypass Phishing Kits Go Mainstream Incident Teardowns
- Detecting MFA Bypass Phishing Kit: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: Phishing Kits Are Now a Subscription Business CIO Briefings