Understanding the Attack Surface: Okta + Entra ID + M365 Session Reuse
In today's enterprise identity architecture, Okta often acts as the identity provider (IdP) for Microsoft Entra ID (formerly Azure AD) federated sign-ins. When a user authenticates through an Okta-integrated browser flow, a session is established and tokens are issued, which are then reused across Microsoft 365 web applications like Outlook, SharePoint, and Teams with no additional prompts.
These sessions are persistent and transferable, relying on authentication cookies that travel across applications within the same user context. Behind the scenes, telemetry including session ID, IP address, user agent, and geo-location is logged but not always acted on in real time.
Office.com is frequently the starting point, but once authenticated, the user gains seamless access to downstream Microsoft apps without triggering reauthentication or new MFA challenges.
How AiTM Phishing Breaks This Model
Adversary-in-the-Middle (AiTM) phishing has evolved to directly target this trust model. Attackers no longer need to steal passwords; they steal the session itself.
Here's how it works in Okta-to-Entra scenarios:
- Reverse-proxy phishing kits (like Evilginx) intercept the full login flow, capturing valid session cookies and tokens in real time.
- Attackers replay these sessions from other machines or geographies, bypassing multi-factor authentication entirely.
- They can then pivot across M365 applications, harvesting emails, downloading files, and monitoring chats, all under the victim's active session.
- Geo/IP mismatches, impossible travel patterns, or sudden device changes within the same session are often the only clues that hijacking has occurred.
How Attackers Exploit Okta and Microsoft 365 with AiTM
OK, so we've just moved from a simple account compromise through an Adversary-in-the-Middle (AiTM) phishing attack to a deeper, more dangerous reality where attackers don't stop at login. They chain techniques together into a full post-exploitation sequence for persistence, data theft, and lateral movement.
Let's walk through what that really looks like.
In this example, we'll focus on Okta federated login flows targeted by a reverse proxy phishing framework like Evilginx:
- These campaigns clone Microsoft and Okta login screens
- They capture session tokens instead of passwords
- MFA doesn't matter; it's already been passed
- Attackers inject those tokens into their own browser session
- They instantly gain access to Outlook, SharePoint, and Teams without triggering reauthentication or alerts
And this is just the foothold. Once inside, attackers often pivot: dropping remote access tools, manipulating permissions, or scanning for sensitive files and credentials to escalate access. What began as a phishing email becomes a multi-pronged attack chain that's incredibly hard to detect and contain.
Even low-privilege accounts can open the door to broader compromise when session hijacking is in play. The effectiveness and scalability of AiTM phishing make it one of the most dangerous techniques in the modern attacker's playbook.
How Secto Detects and Stops AiTM Attacks
Secto protects identity flows by monitoring for irregular or suspicious session behavior that commonly occurs during Adversary‑in‑the‑Middle attacks. Instead of relying solely on login events, Secto evaluates the broader context of how a session is created, where it's used, and how it moves across applications.
When activity deviates from what is expected for a legitimate user, Secto identifies the behavior as potentially malicious and enables rapid defensive actions:
- Sudden changes in location
- Device characteristics anomalies
- Unusual app access patterns
This approach provides strong visibility and protection against session hijacking attempts in federated environments like Okta and Microsoft 365, without depending on any single authentication step.
Conclusion
Adversary‑in‑the‑Middle attacks targeting Okta‑Entra flows represent one of the fastest‑growing and most effective forms of modern phishing. By exploiting session tokens instead of passwords, attackers can silently bypass MFA, pivot across Microsoft 365 apps, and impersonate users with alarming ease. Traditional security tools often fail to see this activity because the attack happens after authentication, not before it.
Secto shifts the advantage back to defenders by bringing clarity, visibility, and real‑time detection to the session layer where today's attacks actually succeed. By understanding how sessions behave, how identity flows work, and when patterns deviate from trusted norms, Secto enables organizations to contain threats before they become breaches.