Decision RecordActivePublished without chair review

Contain Microsoft 365 session theft

Microsoft 365 account containment

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
High
Section support
High confidence · 1/8 backed · 2 gaps · panel
Severity
High
Assessed severity
Panel
AI roles · 1 disagreement
Freshness · v1
Last updated today
Last revised 2026-09-08
Active4 evidence references · Published 08 Sep 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

Preserve identity evidence, block sign-in, revoke sessions and refresh tokens, reset credentials, remove persistence and unauthorized grants, hunt for token reuse, and require phishing-resistant authentication before restoring access.

Public guidance

Current public guidance · the full record

Current public value version · v1
01

What to do now

At a glance

The edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.

02

Why now

Under review

BigBear 2.0 captures Microsoft 365 session material after a victim completes a phishable authentication factor, so changing the password alone does not address an already copied bearer session.

Once theft is suspected, evidence preservation, sign-in blocking, revocation, and replay hunting must begin before access is restored.

This position reflects the Roundtable evidence available through 8 September 2026 and remains qualified because application-specific Microsoft revocation documentation is absent.

03

Who is affected

Under review

Microsoft 365 account holders who complete push, OTP, or another proxyable factor through a BigBear 2.0 or Evilginx2-proxied login face credential and session-cookie capture followed by bearer-session replay.

Microsoft 365 and relying applications that accept the copied session remain exposed until revocation, expiry, or another control makes it unusable.

Identity and security operators must preserve evidence, remove unauthorized grants and persistence, verify each application’s revocation state, and control restoration.

For users required to use FIDO2/WebAuthn without a proxyable fallback, the packet does not show a cryptographic bypass; the reported tactic instead steers users away from that method.

04

What supports this

Supported

Support — The identity architect’s account of the cited CloudSEK reporting says Evilginx2 proxied the genuine Microsoft 365 login, captured credentials and the resulting session cookie after a phishable factor, and enabled replay of that bearer session.

Support — The moderator’s synthesis confirms that BigBear 2.0 used a downgrade tactic to steer victims away from FIDO2/WebAuthn rather than bypassing WebAuthn cryptography.

Support — The evidence audit found the synthesis and expert discussion consistent in supporting sign-in blocking, session and refresh-token revocation, credential reset, persistence investigation, and phishing-resistant authentication.

Evidence gap — A retrieval record contains only a search summary, not substantive Microsoft documentation that verifies revocation behavior across applications and token types.

05

How the Roundtable reached this

Under review

The decision scout identified containment as the operational question because BigBear 2.0 uses Evilginx2 to steal Microsoft 365 credentials and post-authentication session material.

The identity architect and moderator resolved the central terminology dispute: this is session theft after a phishable factor, not a cryptographic break of MFA or WebAuthn.

The evidence auditors supported the containment sequence but found no substantive Microsoft documentation verifying revocation behavior across applications and token types.

The boundary reviewer confirmed that qualified defensive guidance was public-safe, the linker found no prior record to update, and the arbiter selected a new operational decision while retaining the vendor-evidence caveat.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 11 candidate signals.
  • Linker (AI panel role)Linker evaluated 11 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 26 evidence signals; 15 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 16 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 11 decision envelopes.

Key disagreement

Scout (AI panel role)

Reported organization counts conflict, and revocation effectiveness varies by application, token type, and expiry.

Arbiter outcome

Arbiter outcome: new decision record. The packet provides strong support for a new, public-safe operational containment decision, with only an enrichment gap concerning vendor documentation.

Candidates considered

Considered 11 candidates · opened 1 · 10 not opened (10 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06

What is uncertain

Missing

Revocation timing and coverage remain uncertain across Microsoft 365 applications, relying applications, token types, and expiry states.

Reported organization counts also conflict. The packet does not establish an Entra platform vulnerability, a cryptographic MFA break, or a WebAuthn bypass; it describes steering victims toward push, OTP, or another proxyable method.

The evidence is bounded to the 8 September 2026 historical replay and lacks substantive vendor documentation.

07

What evidence is missing

Conflicting

The packet lacks substantive Microsoft identity-response and session-revocation documentation showing how blocking sign-in and revoking sessions or refresh tokens behave for each Microsoft 365 application, relying application, token type, and expiry state.

The recorded retrieval entry is only a truncated search summary. The packet also contains no results from application-by-application revocation testing or clean-device re-enrollment validation.

08

What would change this

Under review

Substantive Microsoft documentation establishing exact revocation behavior could narrow or remove the application-and-token qualification.

If validation shows session replay continuing after sign-in blocking and revocation, keep access disabled and extend hunting until the copied sessions expire or become unusable.

Evidence that BigBear 2.0 compromises Entra or WebAuthn cryptography, rather than stealing a bearer session after proxyable authentication, would require a broader platform-level response.

09

What to watch next

Under review

Test whether copied sessions remain usable in every Microsoft 365 and relying application after revocation.

Monitor sign-ins and token use for replay, validate re-enrollment from a clean device, and keep the account blocked until copied sessions can no longer authenticate.

Watch for substantive Microsoft guidance defining revocation timing and coverage by application, token type, and expiry; use it to update the containment sequence.

Sources & context

Evidence basis

4 references
Context
The key distinction is that BigBear 2.0 did not cryptographically break MFA. Evilginx2 proxied the legitimate Microsoft …

The key distinction is that BigBear 2.0 did not cryptographically break MFA. Evilginx2 proxied the legitimate Microsoft 365 login, captured credentials and the session cookie issued after a victim completed a phishable factor, and then enab…

Observed 8 Sept 2026
Context
Interaction
Observed 8 Sept 2026
Context
Summary: The immediate priority is compromised privileged infrastructure, not the day’s most dramatic headline. Vendor g…

Summary: The immediate priority is compromised privileged infrastructure, not the day’s most dramatic headline. Vendor guidance and exploitation reporting support same-day containment and hunting across ScreenConnect, N-central, SonicWall S…

Observed 8 Sept 2026
Revision trail

Public value history

1 event on record
1 value version · 1 update · 0 predictions
  1. 08 Sep 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.