Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is abuse of single sign-on or identity federation?

Abuse of single sign-on or identity federation occurs when an offender exploits a trusted identity relationship to access one or more connected services. One compromised session, token or application permission can be accepted by several services without the password being entered again.

A relying application's record of a valid federated identity shows what identity it accepted. It may not show how the original authentication was obtained or who controlled it.

Trace the trust chain

In a federated login, an identity provider authenticates the user and issues an assertion or token that another application trusts. Access can also depend on session cookies, application consent, administrator configuration or long-lived refresh tokens.

Correlate both sides of that relationship:

  • the original identity-provider authentication;
  • device, source and multi-factor records;
  • token issuance, claims and session identifiers;
  • application consent or trust changes;
  • each relying service that accepted the identity; and
  • activity performed within those services.

The relying service may record the identity provider as the immediate source rather than the original device. Shared token or session identifiers, timing and claims can bridge that gap.

Access may outlast a password change

Changing a password does not necessarily revoke existing sessions, refresh tokens or application grants. Preserve issuance, refresh, revocation, consent and sign-out events when reconstructing both the incident and subsequent containment.

One account appearing across several services does not prove the account holder personally visited each one. Report the accepted identity, the authentication route and the evidence of human control as distinct findings.

Key takeaway

Follow federated access from original authentication through token issuance to each relying service, and do not equate a valid account identity with the person controlling the session.

Reference: CIM-263Cyber Incidents & Offender Methods