In Microsoft's Zero Trust security model, the Primary Refresh Token (PRT) is the linchpin of single sign-on (SSO) on devices joined or registered with Microsoft Entra ID. Issued after a successful MFA challenge and bound to the device's hardware TPM, the PRT carries cryptographic claims certifying device compliance and posture. However, modern adversary tactics, including advanced AiTM phishing and infostealer malware, reveal a critical blind spot: the replay of derived session credentials from unauthorized external IP addresses.
Attack Anatomy: T1550.004 and Token Replay
Under MITRE ATT&CK technique T1550.004 (Web Session Cookie Hijacking), attackers do not necessarily require physical access to the device or the capability to extract hardware-bound private keys from the TPM:
- Local SSO Abuse (Roadtoken / Mimikatz): Operating under the victim's user context, attackers leverage Windows CloudAP and Web Account Manager (WAM) APIs to generate valid refresh credentials (such as
x-ms-RefreshTokenCredentialcookies) without triggering TPM extraction alerts. - Browser Session Hijacking: When a PRT is utilized to authenticate to web workloads, session cookies (e.g.,
ESTSAUTH) are stored in browser process memory or local storage. Infostealers extract these artifacts directly. - Conditional Access Bypass: The adversary injects the stolen token into an external browser session. Because the existing session token already satisfies compliance and MFA claims, Conditional Access engines evaluate the request as trusted, skipping interactive challenges.
The Native Telemetry Blind Spot
In standard Microsoft Entra ID sign-in logs, these fraudulent authentications register as Error Code 0 (Success), with IsCompliant = true and authentication processing details confirming PRT satisfaction. The discrepancy only emerges when correlating the actual egress public IP reported by Defender for Endpoint against the incoming sign-in IP recorded by Entra ID.
Advanced Hunting Detection (KQL)
The following Advanced Hunting query performs real-time telemetry cross-correlation between DeviceInfo and AADSignInEventsBeta to detect PRT or compliant session replay originating outside the endpoint's known network perimeter:
let lookback = 24h;
let HostEgress = DeviceInfo
| where Timestamp > ago(lookback) and isnotempty(AadDeviceId) and isnotempty(PublicIP)
| summarize KnownPublicIPs = make_set(PublicIP) by AadDeviceId;
AADSignInEventsBeta
| where Timestamp > ago(lookback) and ErrorCode == 0 and isnotempty(DeviceId)
| extend AuthDetails = tostring(AuthenticationProcessingDetails)
| where AuthDetails has "PRT" or IsCompliant == true
| lookup kind=inner HostEgress on $left.DeviceId == $right.AadDeviceId
| where not(set_has_element(KnownPublicIPs, IPAddress))
| project Timestamp, AccountUpn, AadDeviceId = DeviceId, ReplayedIP = IPAddress, KnownHostIPs = KnownPublicIPs, Application, UserAgentAutomated SOAR Remediation with Akuity SOC
When credential replay occurs, manual response times leave sensitive data exposed across Microsoft Purview. Akuity SOC automates defense at machine speed:
- Instant In-App AI Validation: Akuity SOC's in-app AI assistant analyzes session claims and validates IP divergence in under 2 seconds in the background, without any payload leakage to external public web utilities.
- One-Click Coordinated Response: Analysts trigger
revokeSessions()andconfirmUserCompromised()directly from the evidence inventory to invalidate active Entra ID tokens, simultaneously executingisolateDevice()on the physical endpoint via Defender for Endpoint. - Zero Trust Governance: Every Server Action requires strict analyst MFA AAL2 verification and is recorded in an immutable audit ledger compliant with NIS 2 and SOC 2 Type II frameworks.
Technical FAQ
Does Continuous Access Evaluation (CAE) mitigate this risk automatically?
Not by default. While CAE intercepts critical events such as user disablement or explicit administrative password resets in near real-time, it does not dynamically revoke access on mere IP drift unless strict CAE IP network policies are configured and violated.
Why doesn't the Hardware TPM prevent session hijacking?
The TPM securely binds the core PRT secret key to the motherboard. However, it does not safeguard the ephemeral session tokens or browser cookies generated downline by legitimate system processes once the initial PRT challenge has succeeded.
Stop identity bypass attacks today: Experience autonomous containment with Akuity SOC. Start your 14-day free trial, no credit card required.