Preliminary research
Nested APP Authentication — Undocumented Risk and Conditional Access Bypass
Nested APP Authentication — Undocumented Risk and Conditional Access Bypass (Talk-page copy)
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Conference page for a study of Microsoft Nested App Authentication. The associated presentation varies broker, nested-client and resource identities and compares Conditional Access inclusion and exclusion policies. Exploitation assumes a usable refresh token and delegated permissions; the tests do not show universal policy bypass.
Record
- Document
- Nested APP Authentication — Undocumented Risk and Conditional Access Bypass (Talk-page copy)
- Researcher
- Shang-De Jiang and Jun Sheng Shi
- Published by
- TROOPERS
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Shang-De Jiang and Jun Sheng Shi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .