Netwrix 1Secure delivers unified visibility across data and identity - free for 14 days with full access. Start a free trial

Upcoming webinars

For All audiences

Inside Entra ID Authentication: How Tokens, MFA, and Conditional Access Work and Where Attackers Break the Chain

00

days

00

hours

00

minutes

Identity Threat Detection & Response

Reserve your spot

Organizations invest heavily in implementing Entra ID’s MFA, Conditional Access, Identity Protection, and passwordless authentication features. Yet attackers continue to bypass these controls through token theft, MFA fatigue, legacy authentication, and session abuse. To understand why, you first need to understand how Entra ID actually processes a sign-in and how these controls work together – and critically – where there are security dependencies between controls.

In this real training for free event, I'll walk through the Entra ID authentication pipeline from beginning to end, following a user from initial authentication through MFA, Conditional Access evaluation, token issuance, session management, and access to applications. Along the way, we'll look at the places where attackers most often succeed in bypassing or weakening those protections.

We'll examine how legacy authentication can circumvent modern controls, why some MFA methods are far stronger than others, how MFA fatigue attacks work, what number matching actually protects against, and why token theft has become such an attractive technique for attackers. We'll also look at Continuous Access Evaluation, session controls, risky sign-ins, and how Entra uses signals to continuously evaluate trust after a user has already signed in.

Some of the things we’ll explore are:

  • Modern vs. legacy authentication
  • MFA enforcement and common gaps
  • MFA fatigue attacks and number matching
  • Phishing-resistant authentication methods
  • Conditional Access policy evaluation
  • Token issuance and token lifetime considerations
  • Session persistence risks
  • Continuous Access Evaluation (CAE)
  • Risk-based access and Identity Protection

We'll also look at how Netwrix PingCastle can help you uncover security gaps in your own Entra ID environment and remediate them before attackers exploit them.

My goal is by the end of the session, you'll have a clear mental model of how Entra ID authentication works under the hood, where Microsoft's security controls fit into the process, and which misconfigurations create the biggest opportunities for attackers. I want you to leave with a better understanding of how Entra ID controls can stop real world attacks, how to identify bypass and token theft risks and more.

My sponsor for this real training for free event is Netwrix and Tyler Reese, VP, Identity Product Management at Netwrix is joining me to help talk about Entra ID risks. Tyler will briefly show you how Netwrix PingCastle helps you understand where you’re at risk and what to address first.

Share on

Inside Entra ID Authentication: How Tokens, MFA, and Conditional Access Work and Where Attackers Break the Chain

Speakers

Learn More

Tyler reese headshot

Tyler Reese

VP of Product Management, CISSP