#35 - How Stolen Sessions are Bypassing MFA and How to Finally Stop Them episode artwork

EPISODE · Feb 28, 2026 · 27 MIN

#35 - How Stolen Sessions are Bypassing MFA and How to Finally Stop Them

from The Identity Navigator · host Rohit Agnihotri

Imagine this: Tuesday morning. Security dashboard green. MFA at 100%. Privileged accounts vaulted. Fortress built.Then an attacker logs in as your CFO via a stolen browser cookie. No password guess. No brute force. Your stack? Silent.We dive into Pass-the-Cookie attacks, the elite technique bypassing MFA via infostealer malware and AiTM phishing.We cover:Bearer tokens as the “keycard anyone can use”Microsoft’s Token Protection with PRT + TPM for device-bound proof-of-possessionOkta FastPass, device binding, and ASN/IP session controlsDBSC: Browsers’ revival of Token Binding to kill cookie theft foreverPlus your playbook of what features to Enable.Technical deep dive for IAM leaders.

Imagine this: Tuesday morning. Security dashboard green. MFA at 100%. Privileged accounts vaulted. Fortress built.Then an attacker logs in as your CFO via a stolen browser cookie. No password guess. No brute force. Your stack? Silent.We dive into Pass-the-Cookie attacks, the elite technique bypassing MFA via infostealer malware and AiTM phishing.We cover:Bearer tokens as the “keycard anyone can use”Microsoft’s Token Protection with PRT + TPM for device-bound proof-of-possessionOkta FastPass, device binding, and ASN/IP session controlsDBSC: Browsers’ revival of Token Binding to kill cookie theft foreverPlus your playbook of what features to Enable.Technical deep dive for IAM leaders.

NOW PLAYING

#35 - How Stolen Sessions are Bypassing MFA and How to Finally Stop Them

0:00 27:42

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of The Identity Navigator?

This episode is 27 minutes long.

When was this The Identity Navigator episode published?

This episode was published on February 28, 2026.

What is this episode about?

Imagine this: Tuesday morning. Security dashboard green. MFA at 100%. Privileged accounts vaulted. Fortress built.Then an attacker logs in as your CFO via a stolen browser cookie. No password guess. No brute force. Your stack? Silent.We dive into...

Can I download this The Identity Navigator episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!