Attackers don't need to "break in" if they can simply log in. Infostealers, credential stuffing, session token theft and the hijacking of Single Sign-On (SSO) often grant broad access with a low chance of detection.
Typical signals
- Impossible travel, unusual IdP apps, unknown OAuth apps
- New MFA enrollments, token replay, refresh token abuse
- Credential reuse across VPN, VDI, admin portals and SaaS
Current-state check
- Mitigations: phishing-resistant MFA, device binding, CA policies
- Monitor infostealer exposure (leaked creds) and forced resets
- Protect the IdP: admin segregation, break-glass accounts, logging