Decision RecordActivePublished without chair review
CRT-2026-026008 Sep 2026MORNING EDITIONDaily Roundtable
Contain Microsoft 365 session theft
Preserve identity evidence, block sign-in, revoke sessions and refresh tokens, reset credentials, remove persistence and unauthorized grants, hunt for token reuse, and require phishing-resistant authentication before restoring access.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Under reviewBigBear 2.0 captures Microsoft 365 session material after a victim completes a phishable authentication factor, so changing the password alone does not address an already copied bearer session.
Once theft is suspected, evidence preservation, sign-in blocking, revocation, and replay hunting must begin before access is restored.
This position reflects the Roundtable evidence available through 8 September 2026 and remains qualified because application-specific Microsoft revocation documentation is absent.
Who is affected
Under reviewMicrosoft 365 account holders who complete push, OTP, or another proxyable factor through a BigBear 2.0 or Evilginx2-proxied login face credential and session-cookie capture followed by bearer-session replay.
Microsoft 365 and relying applications that accept the copied session remain exposed until revocation, expiry, or another control makes it unusable.
Identity and security operators must preserve evidence, remove unauthorized grants and persistence, verify each application’s revocation state, and control restoration.
For users required to use FIDO2/WebAuthn without a proxyable fallback, the packet does not show a cryptographic bypass; the reported tactic instead steers users away from that method.
What supports this
SupportedSupport — The identity architect’s account of the cited CloudSEK reporting says Evilginx2 proxied the genuine Microsoft 365 login, captured credentials and the resulting session cookie after a phishable factor, and enabled replay of that bearer session.
Support — The moderator’s synthesis confirms that BigBear 2.0 used a downgrade tactic to steer victims away from FIDO2/WebAuthn rather than bypassing WebAuthn cryptography.
Support — The evidence audit found the synthesis and expert discussion consistent in supporting sign-in blocking, session and refresh-token revocation, credential reset, persistence investigation, and phishing-resistant authentication.
Evidence gap — A retrieval record contains only a search summary, not substantive Microsoft documentation that verifies revocation behavior across applications and token types.
How the Roundtable reached this
Under reviewThe decision scout identified containment as the operational question because BigBear 2.0 uses Evilginx2 to steal Microsoft 365 credentials and post-authentication session material.
The identity architect and moderator resolved the central terminology dispute: this is session theft after a phishable factor, not a cryptographic break of MFA or WebAuthn.
The evidence auditors supported the containment sequence but found no substantive Microsoft documentation verifying revocation behavior across applications and token types.
The boundary reviewer confirmed that qualified defensive guidance was public-safe, the linker found no prior record to update, and the arbiter selected a new operational decision while retaining the vendor-evidence caveat.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 11 candidate signals.
- Linker (AI panel role)Linker evaluated 11 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 26 evidence signals; 15 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 16 public/private findings.
- Arbiter (AI panel role)Arbiter produced 11 decision envelopes.
Key disagreement
Scout (AI panel role)
Reported organization counts conflict, and revocation effectiveness varies by application, token type, and expiry.
Arbiter outcome
Arbiter outcome: new decision record. The packet provides strong support for a new, public-safe operational containment decision, with only an enrichment gap concerning vendor documentation.
Candidates considered
Considered 11 candidates · opened 1 · 10 not opened (10 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingRevocation timing and coverage remain uncertain across Microsoft 365 applications, relying applications, token types, and expiry states.
Reported organization counts also conflict. The packet does not establish an Entra platform vulnerability, a cryptographic MFA break, or a WebAuthn bypass; it describes steering victims toward push, OTP, or another proxyable method.
The evidence is bounded to the 8 September 2026 historical replay and lacks substantive vendor documentation.
What evidence is missing
ConflictingThe packet lacks substantive Microsoft identity-response and session-revocation documentation showing how blocking sign-in and revoking sessions or refresh tokens behave for each Microsoft 365 application, relying application, token type, and expiry state.
The recorded retrieval entry is only a truncated search summary. The packet also contains no results from application-by-application revocation testing or clean-device re-enrollment validation.
What would change this
Under reviewSubstantive Microsoft documentation establishing exact revocation behavior could narrow or remove the application-and-token qualification.
If validation shows session replay continuing after sign-in blocking and revocation, keep access disabled and extend hunting until the copied sessions expire or become unusable.
Evidence that BigBear 2.0 compromises Entra or WebAuthn cryptography, rather than stealing a bearer session after proxyable authentication, would require a broader platform-level response.
What to watch next
Under reviewTest whether copied sessions remain usable in every Microsoft 365 and relying application after revocation.
Monitor sign-ins and token use for replay, validate re-enrollment from a clean device, and keep the account blocked until copied sessions can no longer authenticate.
Watch for substantive Microsoft guidance defining revocation timing and coverage by application, token type, and expiry; use it to update the containment sequence.
Evidence basis
The key distinction is that BigBear 2.0 did not cryptographically break MFA. Evilginx2 proxied the legitimate Microsoft 365 login, captured credentials and the session cookie issued after a victim completed a phishable factor, and then enab…
Summary: The immediate priority is compromised privileged infrastructure, not the day’s most dramatic headline. Vendor guidance and exploitation reporting support same-day containment and hunting across ScreenConnect, N-central, SonicWall S…
Public value history
- 08 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableMorning roundtableConvened 08 Sep 2026Methodology
How the panel reaches a Public Decision Record.