One Stolen Credential. Two Platforms.
Full Access.

No malware. No exploits. Just a username, a password, and a clear path to the data behind them.

See how ThreatDown tracks an identity-led intrusion stage by stage, across Microsoft Entra ID and Okta, and dismantles it before the damage is done. 

Get the guide

By submitting this form, I consent to ThreatDown or an authorized partner contacting me regarding products and services and using my personal data as described in the ThreatDown Privacy Policy.

What’s inside

This guide walks through a realistic identity-led intrusion, built from real-world attack techniques against a hybrid Microsoft Entra ID and Okta environment. routine admin activity into a confirmed attack chain. 

Five stages, one compromised account, and the exact signals ThreatDown Identity Threat Detection & Response (ITDR) uses to turn

  • Stage 1: A password spray across both platforms lands one working credential. 
  • Stage 2: Federation turns a single sign-in after hours into access to both platforms. 
  • Stage 3: Guest access becomes admin access in three steps. 
  • Stage 4: An API token, created outside business hours, opens a door built to stay open. 
  • Stage 5: One exfiltration path gets blocked. The other gets through: 200+ files and 7 archives before ITDR flags it. 

3 things security teams need to know

1

Federation is a lateral movement path most monitoring misses. One compromised Entra ID credential is a compromised Okta credential too, and the pivot needs no second password.

2

Every persistence step in this scenario used a legitimate feature. Three routine actions: external invite, guest-to-member conversion, and admin role grant, took an outsider to a privileged insider. None of it trips a malware signature. 

3

The credential attack is the highest-value moment to catch it. By the time exfiltration starts, two persistence mechanisms are already locked in. 

See the full attack chain, step by step

Get the eBook and follow the intrusion from the first failed login to the final exfiltration attempt, plus the takeaways security teams need to close the gap.