Entra.News - Your weekly dose of Microsoft Entra
Entra.Chat
Stolen Tokens, Agents and Universal CAE: What Global Secure Access Adds to Entra ID
0:00
-50:16

Stolen Tokens, Agents and Universal CAE: What Global Secure Access Adds to Entra ID

Entra ID P1's compliant network makes stolen tokens useless. Alex Pavlovsky and Marilee Turscak on Global Secure Access, AI agents and Universal CAE.

A phished and stolen refresh token is one of the most useful things an attacker can take from your tenant. It is a long-term artifact, which is why so many phishing attempts go after it. Alex Pavlovsky’s answer to that attack is a feature every Entra ID P1 tenant already owns.

Compliant network is part of Global Secure Access, and, like source IP restoration, it comes with Entra ID P1. Put the GSA client on your devices, add one Conditional Access policy that blocks access from anywhere outside the All Compliant Network locations named location, and a stolen refresh token or PRT cookie no longer works from the attacker’s own machine. As Alex puts it, the token itself does not become bound, but your use of it is gated by being on your organization’s compliant network.

Merill is joined by two former colleagues who are Microsoft Entra PMs: Alexander (Alex) Pavlovsky from the Global Secure Access feature team, and Marilee Turscak, who works on helping customers adopt AI safely. They explain why Microsoft built networking into identity, walk through the compliant network policy and a BYOD sign-in with no client installed, and demo a network policy that stops an agent from deleting a file its user is allowed to delete.

Why a stolen token stops working

For phishing itself, Alex is clear that the main line of defence is still stronger credentials that do not involve passwords. Compliant network helps with what comes after: the newer attack patterns where refresh tokens are stolen and replayed.

If your tenant-wide policy says you can only authenticate from a compliant network, you can also only replay refresh tokens from a compliant network. PRTs become unusable unless they are used from a device that has GSA, which means your organization’s device. Alex says the same applies to ROADtools-style attacks with PRT cookies: none of that works with compliant network in place. The signal is also tenant-specific. A GSA device in tenant B satisfies compliant network in tenant B and nowhere else.

In the demo, Alex builds the policy in a few clicks: all users, all resources (so the primary refresh token, Entra ID itself and Microsoft Graph are covered), any network except compliant network locations, then block. Start it in report-only mode, watch who is not coming through compliant network, pilot with a smaller group and expand. You do not need the advanced GSA licences for this, but you do need the GSA client on your devices or a remote network sending the traffic.

And exclude your break glass accounts. Alex has taken many panicked customer calls from admins who forgot, and Marilee locked herself out of a test tenant this way recently.

One engine for identity and network

When Merill joined Microsoft, he couldn’t see why networking belonged to the identity team. Alex explains the reasoning. When identity picks up a signal that a user, session or token is at risk, the network has to hear about it quickly, and passing those signals between separate systems through traditional APIs is too slow at this scale. So Microsoft made the identity engine and the network engine one engine.

That design shows up in source IP restoration. Behind a typical proxy or security service edge, every user looks like they signed in from the provider’s shared IP range. GSA sends the user’s original source IP to Entra securely, so sign-in logs are accurate, Conditional Access can evaluate the user’s own IP, and Identity Protection’s location and impossible travel detections work again. It is also why compliant network works at all: the GSA edge shares a security engine with Entra ID, so it can tell Entra that this is a legitimate GSA device from a specific tenant, and Entra can trust that signal.

The network can tell agents from users

“Agents are super deterministic. They are very resourceful. They do not give up.” Alex also argues that saying no to agents means falling behind your competitors, so the question becomes how to protect their use.

GSA can detect when network access comes from an agent, and its policy rules can match on the HTTP method, the destination and whether a user or an agent is acting. Marilee’s baseline recommendation is to block sensitive actions by agents. In her demo, the Zava helper agent tries to remove a document from Dropbox and gets an “agent is not authorized” error, because a policy called “block agents from destructive actions” blocks the DELETE method for agents only. The user checkbox is left clear, so the person can still delete the file themselves. The logs show the same attribution, which Alex says is valuable even before you apply any policy.

Alex also describes Copilot Studio agents running through GSA with no client anywhere. A Copilot Studio admin checks one box to enable the GSA integration, and with Internet Access and a policy in place, that agent traffic flows through GSA and your policies apply.

BYOD without the client

Marilee shows a user on a personal device with no GSA client. When she signs in, she is prompted to switch to her work browser profile, and from then on Explicit Forward Proxy sends that profile’s traffic through GSA. When she tries to open Facebook, she is blocked inside the work profile and nowhere else on her device. Alex sees the managed Edge profile becoming a sandbox with secure network access and Purview DLP, which could reduce the need for remote browser isolation. The full client still gets the most features, including agent detection, and remote networks are a third way to send traffic through GSA.

Universal CAE now acts on device state

Continuous access evaluation used to depend on applications that understood it, which mostly meant SharePoint, Teams and Exchange. Send an app’s traffic through GSA and it becomes CAE-aware too, including private apps. If an admin is on an SSH session over GSA and Entra flags their identity, Alex says the session is dead within about two to five minutes, even if their token is good for another 90 minutes.

The week before recording, Microsoft added device state support. If Intune or a third-party MDM marks a device non-compliant in Entra ID, GSA asks the user to bring it back into compliance or lose network connectivity. User risk changes and device deletion or disablement also trigger it now. If you already run GSA, you get this without changing anything, which is Merill’s favourite kind of feature.

If you have Entra ID P1 and have never deployed the GSA client, compliant network is the place to start.


About Alexander Pavlovsky

Alexander Pavlovsky is a Product Manager on the Microsoft Entra Global Secure Access feature team. He has been at Microsoft for 22 years. He started in Microsoft Consulting, installing domain controllers and Exchange servers for customers from CDs, then moved to the identity product team as a customer-facing PM in the Entra GTP (Get To Production) team, later CXE (Customer Experience), helping organizations adopt Azure AD.

LinkedIn - https://linkedin.com/in/alexpav

About Marilee Turscak

Marilee Turscak is a Product Manager on the Microsoft Security team focusing on Microsoft Entra. For the past two years she has focused on getting customers deployed across the Microsoft Entra Suite, and she now works on helping customers adopt AI safely and securely.

LinkedIn - https://linkedin.com/in/marilee-turscak


Related Links

Related Entra.Chat Episodes


Chapters

00:00 Cold open
01:14 Intro
01:32 Meet Alex and Marilee
05:18 Why networking became part of identity
10:08 How Global Secure Access works
15:07 Source IP restoration
18:24 Compliant network comes with Entra ID P1
19:51 Compliant network vs stolen tokens
21:47 How compliant network actually works
23:30 BYOD without the client
29:43 Telling agents apart from users
31:02 Baseline: block risky agent actions
34:13 Copilot Studio agents through GSA
37:20 Identity and network teams must converge
39:22 Demo: require a compliant network
43:45 What happens to a stolen token
45:12 Universal continuous access evaluation
49:35 Wrap-up


Podcast Apps

Entra.Chat - https://entra.chat

Apple Podcast - https://entra.chat/apple

YouTube - https://entra.chat/youtube

Spotify - https://entra.chat/spotify

Overcast - https://entra.chat/overcast

Pocketcast - https://entra.chat/pocketcast

Others - https://entra.chat/rss


Merill’s socials

YouTube - youtube.com/@merillx

LinkedIn - linkedin.com/in/merill

Twitter - twitter.com/merill

TikTok - tiktok.com/@merillf

Bluesky - bsky.app/profile/merill.net

Mastodon - infosec.exchange/@merill

Threads - threads.net/@merillf

GitHub - github.com/merill

Discussion about this episode

User's avatar

Ready for more?