Skip to main content
CMS Group Ltd
Services
Capabilities
Industries
Platform
Resource Hub
About
ContactTake the maturity audit

Loading...

CMS Group Ltd

Technology Management Consultancy. Technology, run with intent. Since 1990.

0203 404 4700hello@cms-group.net
United Kingdom

Strategic Technology Insights

Monthly analysis for technology leaders. Zero spam, unsubscribe anytime.

Services

  • Quick quote
  • Operate
  • Secure
  • Modernise
  • Transform
  • Capabilities
  • All Services

Locations

  • London
  • Manchester
  • Birmingham
  • Leeds
  • Bristol
  • Edinburgh
  • Scotland
  • North West

Industries

  • Hospitality
  • Legal
  • Finance
  • Healthcare
  • Manufacturing
  • Other sectors?

Operating model

  • StrategyOS
  • CMS Strata
  • Tools
  • Maturity Audit
  • Risk Calculator

Company

  • About CMS
  • Why CMS
  • Resource Hub
  • Guides
  • Careers
  • Refer a peer
  • Community
  • Contact

ISO 27001

Certified

ISO 9001

Certified

Cyber Essentials Plus

Accredited

Lyra Technology Group

Member

© 2026 CMS Group Ltd. All rights reserved.

Registered in England and Wales · Company no. 02513535

Privacy PolicyTerms of ServiceCookie Policy
Back to Insights Hubtechnology insights

The Rise of Token Theft: How to Shield Your Data from Cyber Attacks

Token Theft is a rising security threat that allows attackers to bypass MFA and enter your systems. Learn how to protect against it.

Oliver Coop
Oliver CoopAuthor
30 September 20244 min read
The Rise of Token Theft: How to Shield Your Data from Cyber Attacks

Understanding Identity Token Theft

Identity token theft occurs when an attacker waits for a legitimate user to obtain a token and then steals it to gain unauthorised access. While most attacks still target passwords, multi-factor authentication (MFA) remains essential. However, as MFA usage increases, attackers are turning to credential bypass attacks like token theft. In 2023 alone, Microsoft detected 147,000 token theft attacks, marking a 111% increase from the previous year.

How Token Theft Works

When you sign into a site or service using your security credentials, including MFA, an identity provider issues your tokens. These tokens describe who you are and what you can do, and you present them to access applications and services. Tokens are stored in the background by your browser, apps, or mobile device management service, so you don’t have to re-enter your credentials every time. If an attacker accesses these tokens and makes a copy, they can access your resources without needing your username, password, or a successful MFA challenge.

Real-World Example of Token Theft

Consider this scenario: A user signs into a cloud storage account using MFA and receives a session token. They click on a malicious link, which installs malware that copies the session token and sends it to the attacker. The attacker then uses the token to access the cloud storage and download confidential documents. Other methods of token theft include copying tokens from network proxies or routers or extracting them from server logs.

Implementing Token Protection

Protect your organisation from token theft protection with Microsoft Entra, Intune, Defender XDR & Windows.

To prevent token theft, it’s essential to bind the token to the device it was issued to, a process known as token protection or token binding. This method, currently in preview, requires apps and services to support token binding. It works with Microsoft Intune enrolment, Outlook, SharePoint, and Microsoft Teams. Token protection ensures that tokens only work on the specific device they were issued to, preventing attackers from using stolen tokens.

Using Conditional Access Policies

Conditional Access policies allow you to require bound tokens to access resources. For example, you can configure policies to target Office 365 Exchange and SharePoint Online, specify Windows as the platform, and require token protection for sign-in sessions. This ties tokens to the device they were issued to, preventing attackers from using stolen tokens.

Additional Defences Against Token Theft

While token protection is the strongest defence against token theft, not all applications or platforms support it. Other countermeasures include requiring managed and compliant devices, enabling Local Security Authority Protection, and using Credential Guard. These settings can be enforced using Windows policies and device compliance checks in Conditional Access.

Detecting and Shutting Down Attacks

Microsoft Entra ID has built-in detections for token theft and evaluates user and sign-in risk automatically. Configuring risk-based access policies allows you to block or revoke tokens when token theft is suspected. Continuous access evaluation enables real-time re-authentication. Additionally, you can enforce location policies and compliant network checks using Microsoft Entra Internet Access.

Conclusion

Token theft is a serious threat to your identity and data security. Microsoft Entra, along with Windows, Microsoft Intune, and Microsoft Defender XDR, can help protect your tokens and stop replay attacks. At CMS Group, we specialise in helping organisations like yours navigate these challenges and implement robust IT strategies. To learn more and to get started, book a consultation with us today via hello@cms-group.net or call 0203 4044 700.

 

By taking proactive steps to protect your tokens, you can significantly enhance your security posture and safeguard your valuable data. If you need expert guidance on this or any other IT strategy considerations, CMS Group is here to help. Contact us today to schedule a consultation and let us assist you in fortifying your defences against token theft and other cyber threats.

token theftcyber securityMFAidentityUK business
Share

What's your next step?

Strategy is already in. Benchmark maturity, then align next actions with a CMS strategist.

Benchmark your maturityDiscuss your results

Subscribe to Insights Hub

Get evidence-led insight on governance, risk, and technology leadership.

Related Articles

Cyber Security Governance UK: Why NCSC Drills Are Your Best Insurance Policy
technology insights

Cyber Security Governance UK: Why NCSC Drills Are Your Best Insurance Policy

Most Incident Response Plans are dusty PDFs that fail when panic strikes. We explore how to turn the NCSC's "Exercise in a Box" into a powerful asset for Cyber Security Governance in the UK, satisfying insurers and protecting your Board.

Oliver Coop
Oliver Coop
3 min
1 Dec 2025
Economic Impact of Cyber Attacks UK: The £14.7bn Invoice
technology insights

Economic Impact of Cyber Attacks UK: The £14.7bn Invoice

The "average" cyber attack now costs £195k, but for high-value sectors, the reality is far worse. We analyse the new government data on IP theft, fraud, and systemic rise, and what it means for your bottom line.

Oliver Coop
Oliver Coop
3 min
1 Dec 2025
The JLR Cyber Attack: Why Your Antivirus is No Longer Enough for 24/7 Protection
technology insights

The JLR Cyber Attack: Why Your Antivirus is No Longer Enough for 24/7 Protection

In late 2025, a cyber attack brought one of the UK's largest manufacturers, Jaguar Land Rover (JLR), to a standstill. It wasn't just a data breach; it was an operational catastrophe.

Oliver Coop
Oliver Coop
4 min
30 Sept 2025