Microsoft 365 Session Hijacking
Security AwarenessWhen you are already signed in to Microsoft 365, attackers can hijack your account without a login screen, without triggering MFA, and without ever knowing your password. Here is how it works, and what stops it.
The shift in attack surface
Traditional phishing steals your password. Session hijacking steals the proof you are already logged in — your access tokens or session cookies. MFA offers no protection once a valid session or delegated token is in the attacker’s hands.
0
Login screens shown to victim
0
MFA challenges triggered
1
Account compromised (initial scope)
How the attack happens
Two methods. The malware attack shows no popup at all. The consent-phishing attack shows a real Microsoft screen, but it can flash past in 2–3 seconds if you click instinctively.
Most common no-login vector
OAuth Consent Phishing
-
1
You receive a convincing email — “Approve access to review this shared file” or “Connect your account to view the document.”
-
2
You click the link. Because you are already signed in, Microsoft skips straight to a real consent screen — hosted on microsoftonline.com.
-
3
The screen looks like a trusted tool (fake DocuSign, SharePoint viewer). It requests: read your emails, access your files, send messages on your behalf.
-
4
You click Accept.
-
5
The attacker’s app now has permanent delegated access — fresh access tokens and refresh tokens — for your mailbox, OneDrive, and Teams.
Outcome
Full persistent access to your account from anywhere, with no further MFA challenge. The attacker registers a malicious app in advance; you supply the authorisation.
Warning sign
Unexpected Microsoft consent screens asking for broad permissions.
Silent browser attack
Token Theft via Malware
-
1
You click a link disguised as a document, invoice, or “view file” button.
-
2
The link silently downloads malware or tricks you into running hidden code.
-
3
The malware scans your open browser (Chrome, Edge) and extracts your active Microsoft 365 session tokens and cookies.
-
4
Stolen tokens are sent to the attacker’s infrastructure.
-
5
The attacker pastes the tokens into their own tools — no login screen, no MFA prompt.
Outcome
Instant full account access. Your existing session was already trusted; the malware simply steals the proof of that trust.
Warning sign
No visible sign — everything looks normal during and after the attack.
Blast radius
The initial hijack affects only the account whose session was stolen. However, scope can escalate rapidly.
Initial impact
Standard user- •Read all email, calendar, and files
- •Send email as the victim
- •Access Teams chats and meetings
- •Download OneDrive and SharePoint content
Escalation risk
Admin account- •Add persistent malicious apps to the tenant
- •Create new admin accounts
- •Disable security policies and MFA
- •Access all users’ data across the organisation
Priority action if an admin account is compromised
Treat it as a full tenant breach. Revoke all sessions immediately via Azure AD and audit all consented applications before resuming normal operations.
Microsoft 365 already gives you excellent defences
These are not optional extras — they are the essential foundation and you should absolutely use all of them.
Enable strict admin consent policies
Prevent users from approving third-party apps without admin sign-off. Stops OAuth consent phishing cold.
Use Conditional Access with token protection
Azure AD Conditional Access rules and token binding block replayed stolen tokens from unfamiliar devices or locations.
Keep Endpoint Detection & Response (EDR) running on every device
EDR catches token-stealing malware before it can exfiltrate your session data from the browser.
Never click Accept on an unexpected consent screen
Legitimate tools do not arrive unannounced via email. If you did not request it, call IT before clicking anything.
Treat unexpected link clicks as high-risk
Do not open unexpected attachments or “view file” buttons — even from known senders, whose accounts may themselves already be compromised.
These steps block the vast majority of attacks — but not all of them.
Determined attackers still get through. When they do, they look exactly like a legitimate user inside your Microsoft 365 tenant. From Microsoft’s perspective, the session token is valid. The login happened. Everything seems normal. The attack is already invisible inside your environment.
Bottom line
An active Microsoft 365 session is a credential. Anything that steals it — a malicious app consent or silent token-harvesting malware — gives an attacker the same full access as having your password, without ever triggering a fresh login or MFA prompt. Microsoft 365’s defences are excellent and you should use every one of them. But when a determined attacker gets through, they are invisible inside your tenant. That is the gap.
The next layer of protection
That’s where Martyria makes all the difference
A plain-English picture
Microsoft 365 locks the front door extremely well. Martyria stands on the roof with binoculars and a camera, watching everything that actually moves on your network. Together they give you protection that is far stronger than either one alone.
Martyria – The Witnesses is an independent watchdog that sits outside your Microsoft 365 environment and outside your computers. It continuously records your network traffic — the actual data flowing in and out — via your SoftSol MikroTik router. So even if an attacker has stolen a session token and is quietly reading emails, downloading files, or sending messages as you, Martyria sees the unusual patterns:
-
Connections to strange IP addresses or known bad destinations after the token was stolen
-
Sudden data leaving your network that does not match normal business behaviour
-
Malware phoning home to the attacker after it silently stole your session tokens
Why this matters: tamper-proof evidence
Because Martyria’s evidence is stored on a completely separate system, attackers cannot delete or hide it — even if they fully compromise your Microsoft 365 tenant or your laptops. You get early alerts, a clear timeline of exactly what happened, and rock-solid proof for your insurer or regulators.
Continuous, tamper-proof network monitoring for your business — easy to add alongside your existing Microsoft 365 setup.