u/Imagnaryk-Benefit310

▲ 1 r/AZURE

Is device-bound authentication the most effective way to prevent stolen session tokens?

been reading up on device-bound tokens as a way to stop the stolen token replay problem we've been dealing with.

a token tied to a specific device is a lot less useful to an attacker who lifted it remotely, which is the whole point. rollout looks straightforward for managed devices but our byod population is a real complication. is device binding actually closing this gap for people who've deployed it, or have attackers already found workarounds, and how are you handling the byod side of it?

reddit.com
u/Imagnaryk-Benefit310 — 2 days ago

Which identity threat detection and response tools provide useful context instead of more alerts?

Our old ITDR setup fired constantly and required someone to manually piece together five data sources before an alert meant anything.
what actually cut the noise was moving to one unified identity record that ties the person, the session, and the resource together instead of firing three disconnected pings for the same event. has anyone found something that reduces analyst workload instead of adding another dashboard, and what changed for you when you switched?

reddit.com
u/Imagnaryk-Benefit310 — 3 days ago