#35 - How Stolen Sessions are Bypassing MFA and How to Finally Stop Them episode artwork

EPISODE · Feb 28, 2026 · 27 MIN

#35 - How Stolen Sessions are Bypassing MFA and How to Finally Stop Them

from The Identity Navigator · host Rohit Agnihotri

Imagine this: Tuesday morning. Security dashboard green. MFA at 100%. Privileged accounts vaulted. Fortress built.Then an attacker logs in as your CFO via a stolen browser cookie. No password guess. No brute force. Your stack? Silent.We dive into Pass-the-Cookie attacks, the elite technique bypassing MFA via infostealer malware and AiTM phishing.We cover:Bearer tokens as the “keycard anyone can use”Microsoft’s Token Protection with PRT + TPM for device-bound proof-of-possessionOkta FastPass, device binding, and ASN/IP session controlsDBSC: Browsers’ revival of Token Binding to kill cookie theft foreverPlus your playbook of what features to Enable.Technical deep dive for IAM leaders.

Episode metadata supplied by the publisher feed · Published Feb 28, 2026

Embed this episode

Ready to play

#35 - How Stolen Sessions are Bypassing MFA and How to Finally Stop Them

0:00 27:42

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Identity Navigator?

This episode is 27 minutes long.

When was this The Identity Navigator episode published?

This episode was published on February 28, 2026.

Can I download this The Identity Navigator episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!