Entra ID & IdentityHow-To & HardeningRetrospectives

How to Sanitize Support Uploads and Bind Tokens to Devices

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2023, written in 2026 with the benefit of hindsight.

HAR files shared with support teams can contain live session tokens. Token protection and device-bound sessions limit what a stolen token can do. Here is how to address both.

Part 1: Sanitize support uploads

  • Before sharing HAR files: use a HAR sanitizer tool (Cloudflare and Okta published open-source sanitizers) to remove cookies, authorization headers and tokens.
  • Policy: require staff to sanitize HAR files and other diagnostic logs before uploading to any vendor.
  • Prefer screen recordings or screenshots when possible.
  • After sharing: sign out of the session captured, revoke sessions, or change the password so captured tokens become invalid.
  • Vendor requirements: ask vendors whether they automatically scrub uploaded files and how long they retain them.

Part 2: Bind tokens to devices in Entra ID

Token protection (a Conditional Access session control) ensures sign-in session tokens are bound to the device they were issued to. A token copied from a HAR file or stolen by malware can't be replayed on another device.

  1. Check supported scenarios: token protection supports specific clients and resources (for example, Exchange Online and SharePoint Online with supported Windows desktop apps), with coverage growing over time.
  2. Create a Conditional Access policy for a pilot group with Require token protection for sign-in sessions.
  3. Run in report-only mode and review results.
  4. Enforce for admins and high-risk users first.

Part 3: Strengthen admin sessions

  • Require compliant devices for admin portals.
  • Short sign-in frequency for admin roles.
  • Phishing-resistant MFA.
  • Continuous Access Evaluation enabled.

Verify

Test by replaying a session cookie from a test account on another device in a lab — it should be rejected for protected resources.

token protection conditional accessOkta support HAR files2023

More on this story