
It took one password to compromise two identity platforms
A stage-by-stage walkthrough of a realistic attack across Microsoft Entra ID and Okta, and exactly where the intrusion gets shut down.
Attackers don’t need malware or a zero-day to take over an identity. They need one working password. From there, legitimate platform features do the rest: sign-ins, invites, role changes, and API tokens. Nothing that trips an antivirus alert.
Our new eBook walks through exactly that kind of intrusion against a fictional target organization. A password spray lands a valid credential — a sign-in from an unexpected location and hour follows. Then, a federation pivot turns one compromised Microsoft Entra ID account into full access across Okta as well.

From there, the attacker builds persistence two different ways: inviting an external identity into the tenant and quietly escalating it to admin in Entra ID, and creating a long-lived API token in Okta outside normal business hours. The exfiltration attempts that follow, a blocked SSO launch and a 202-file OneDrive download, plus 7 downloaded archives, play out the same way. Ordinary actions that only become alarming in context.
That context is what ThreatDown Identity Threat Detection & Response (ITDR) provides. Every stage in the eBook comes with a real ITDR alert view: the identity involved, the anomaly that triggered it, and how it connects to everything before and after it in the same session. The scenario was designed, simulated, and documented by Paolo Bacchiocchi and Leonardo Giannoni of the ThreatDown Threat Research Team.
See the full attack chain, stage by stage, and exactly where ITDR shuts it down.
20
26Cybercrime in the Age of AI
AI is rewiring the cybercrime ecosystem.
You have six months to prepare.
20
26Cybercrime in the Age of AI
AI is rewiring the cybercrime ecosystem.
You have six months to prepare.