How a Private Sector Bank Closed Its Microsoft 365 Identity Attack Path in Three Weeks
A clean annual VAPT had never touched the identity plane. A full-chain attack-path assessment reached mailbox and document access in under four hours — and produced the Conditional Access changes that closed it.
Client: Leading Private Sector Bank
The Challenge
A Clean VAPT Report and an Exposed Tenant Are Not Contradictory
The bank's annual network and application penetration tests came back clean, as they had for years. Microsoft 365 had never been assessed as an identity plane — not because it was considered low risk, but because it fell outside how VAPT scope had always been written. With device-code phishing being sold as a subscription service and targeting Indian financial institutions, the board asked a question the existing assurance programme could not answer.
- Conditional Access policies authored for interactive browser sign-in, leaving device-code and legacy authentication flows uncovered
- No alerting on new device registrations in Entra ID — the persistence mechanism that survives a password reset
- Audit configuration recorded file downloads but not previews, page views or searches
- Incident runbook ended at password reset, with no session revocation or device de-registration step
- MFA enforced, but via TOTP and SMS — neither of which stops an authentication that the user genuinely completes
The Solution
Full-Chain Identity Attack-Path Assessment Against the Live Tenant
A three-week objective-based engagement run against the production tenant under an agreed rules-of-engagement document, with an out-of-band channel open to the CISO throughout. Testing followed the full chain rather than isolated techniques, because the controls that fail are usually further along than expected.
Services used
Our approach
- 01 External reconnaissance: exposed authentication endpoints and which flows answered
- 02 Device-code phishing against an agreed target population, with consent measured rather than password entry
- 03 OAuth token capture, followed by device registration into the tenant and Primary Refresh Token acquisition
- 04 Legacy and non-interactive authentication paths tested against existing Conditional Access coverage
- 05 Post-access collection via Graph — search, preview and page-view against document libraries
- 06 Detection assessment: every action set against what the SOC saw and what the logs retained
- 07 Purple-team walkthrough with the SOC, then retest after remediation
The Results
Mailbox and Document Access in Under Four Hours; Every Path Closed in Three Weeks
The engagement reached sensitive document libraries without ever obtaining a password, and without triggering a single alert. The resulting Conditional Access and audit changes closed each step of the chain, verified on retest.
Ready to discuss your security needs?
Talk to our team about a similar engagement for your organisation.
Request a Scoping Call