Microsoft 365How-To & HardeningNews

How to Use Token Protection and Compliant-Device Policies Against Token Theft

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

MFA-bypass phishing kits steal tokens rather than passwords. Two Entra ID controls make stolen tokens much less useful: token protection and compliant-device requirements. Here is how to deploy them.

Control 1: Require compliant devices

If Microsoft 365 access requires a device enrolled and compliant in Intune, a token stolen and replayed from an attacker's computer fails the device check.

  1. Enroll corporate Windows, macOS, iOS and Android devices in Intune with compliance policies.
  2. Create a Conditional Access policy for Office 365 (and other sensitive apps) requiring Require device to be marked as compliant (or hybrid joined).
  3. For personal devices, allow browser-only access with app-enforced restrictions or app protection policies for mobile apps.
  4. Pilot, then enforce.

Control 2: Token protection

Token protection binds sign-in session tokens to the device they were issued to.

  1. Review supported platforms, clients and resources (coverage has expanded over time for Windows, and for Exchange Online, SharePoint Online and Teams with supported apps).
  2. Create a Conditional Access policy with the session control Require token protection for sign-in sessions for a pilot group.
  3. Use report-only mode to identify unsupported clients.
  4. Expand to administrators and high-risk users first.

Control 3: Phishing-resistant MFA

Require passkeys or FIDO2 for high-risk users. These can't be phished through proxy sites.

Supporting controls

  • Block device code flow.
  • Continuous Access Evaluation for fast revocation.
  • Identity Protection risk-based policies.
  • Short sign-in frequency for sensitive apps on unmanaged devices.

Verify

Test in a lab: replay a session token from a pilot user on a different, unmanaged device. Access to protected resources should be denied.

Sources

  1. Source
entra token protectionKali365 PhaaS2026

More on this story