Microsoft 365 Session Hijacking

Security Awareness

When you are already signed in to Microsoft 365, attackers can hijack your account without a login screen, without triggering MFA, and without ever knowing your password. Here is how it works, and what stops it.

The shift in attack surface

Traditional phishing steals your password. Session hijacking steals the proof you are already logged in — your access tokens or session cookies. MFA offers no protection once a valid session or delegated token is in the attacker’s hands.

0

Login screens shown to victim

0

MFA challenges triggered

1

Account compromised (initial scope)

How the attack happens

Two methods. The malware attack shows no popup at all. The consent-phishing attack shows a real Microsoft screen, but it can flash past in 2–3 seconds if you click instinctively.

Most common no-login vector

OAuth Consent Phishing

Approve-app trick
  1. 1

    You receive a convincing email — “Approve access to review this shared file” or “Connect your account to view the document.”

  2. 2

    You click the link. Because you are already signed in, Microsoft skips straight to a real consent screen — hosted on microsoftonline.com.

  3. 3

    The screen looks like a trusted tool (fake DocuSign, SharePoint viewer). It requests: read your emails, access your files, send messages on your behalf.

  4. 4

    You click Accept.

  5. 5

    The attacker’s app now has permanent delegated access — fresh access tokens and refresh tokens — for your mailbox, OneDrive, and Teams.

Outcome

Full persistent access to your account from anywhere, with no further MFA challenge. The attacker registers a malicious app in advance; you supply the authorisation.

Warning sign

Unexpected Microsoft consent screens asking for broad permissions.

Silent browser attack

Token Theft via Malware

Session hijack
  1. 1

    You click a link disguised as a document, invoice, or “view file” button.

  2. 2

    The link silently downloads malware or tricks you into running hidden code.

  3. 3

    The malware scans your open browser (Chrome, Edge) and extracts your active Microsoft 365 session tokens and cookies.

  4. 4

    Stolen tokens are sent to the attacker’s infrastructure.

  5. 5

    The attacker pastes the tokens into their own tools — no login screen, no MFA prompt.

Outcome

Instant full account access. Your existing session was already trusted; the malware simply steals the proof of that trust.

Warning sign

No visible sign — everything looks normal during and after the attack.

Blast radius

The initial hijack affects only the account whose session was stolen. However, scope can escalate rapidly.

Initial impact

Standard user
  • Read all email, calendar, and files
  • Send email as the victim
  • Access Teams chats and meetings
  • Download OneDrive and SharePoint content

Escalation risk

Admin account
  • Add persistent malicious apps to the tenant
  • Create new admin accounts
  • Disable security policies and MFA
  • Access all users’ data across the organisation

Priority action if an admin account is compromised

Treat it as a full tenant breach. Revoke all sessions immediately via Azure AD and audit all consented applications before resuming normal operations.

Microsoft 365 already gives you excellent defences

These are not optional extras — they are the essential foundation and you should absolutely use all of them.

M365 Technical

Enable strict admin consent policies

Prevent users from approving third-party apps without admin sign-off. Stops OAuth consent phishing cold.

M365 Technical

Use Conditional Access with token protection

Azure AD Conditional Access rules and token binding block replayed stolen tokens from unfamiliar devices or locations.

M365 Technical

Keep Endpoint Detection & Response (EDR) running on every device

EDR catches token-stealing malware before it can exfiltrate your session data from the browser.

Behaviour

Never click Accept on an unexpected consent screen

Legitimate tools do not arrive unannounced via email. If you did not request it, call IT before clicking anything.

Behaviour

Treat unexpected link clicks as high-risk

Do not open unexpected attachments or “view file” buttons — even from known senders, whose accounts may themselves already be compromised.

These steps block the vast majority of attacks — but not all of them.

Determined attackers still get through. When they do, they look exactly like a legitimate user inside your Microsoft 365 tenant. From Microsoft’s perspective, the session token is valid. The login happened. Everything seems normal. The attack is already invisible inside your environment.

Bottom line

An active Microsoft 365 session is a credential. Anything that steals it — a malicious app consent or silent token-harvesting malware — gives an attacker the same full access as having your password, without ever triggering a fresh login or MFA prompt. Microsoft 365’s defences are excellent and you should use every one of them. But when a determined attacker gets through, they are invisible inside your tenant. That is the gap.

The next layer of protection

That’s where Martyria makes all the difference

A plain-English picture

Microsoft 365 locks the front door extremely well. Martyria stands on the roof with binoculars and a camera, watching everything that actually moves on your network. Together they give you protection that is far stronger than either one alone.

Martyria – The Witnesses is an independent watchdog that sits outside your Microsoft 365 environment and outside your computers. It continuously records your network traffic — the actual data flowing in and out — via your SoftSol MikroTik router. So even if an attacker has stolen a session token and is quietly reading emails, downloading files, or sending messages as you, Martyria sees the unusual patterns:

  • Connections to strange IP addresses or known bad destinations after the token was stolen

  • Sudden data leaving your network that does not match normal business behaviour

  • Malware phoning home to the attacker after it silently stole your session tokens

Why this matters: tamper-proof evidence

Because Martyria’s evidence is stored on a completely separate system, attackers cannot delete or hide it — even if they fully compromise your Microsoft 365 tenant or your laptops. You get early alerts, a clear timeline of exactly what happened, and rock-solid proof for your insurer or regulators.

Visit Martyria – The Witnesses

Continuous, tamper-proof network monitoring for your business — easy to add alongside your existing Microsoft 365 setup.