Web Hack List

Preliminary research

Nested APP Authentication — Undocumented Risk and Conditional Access Bypass

Nested APP Authentication — Undocumented Risk and Conditional Access Bypass (Talk-page copy)

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Conference page for a study of Microsoft Nested App Authentication. The associated presentation varies broker, nested-client and resource identities and compares Conditional Access inclusion and exclusion policies. Exploitation assumes a usable refresh token and delegated permissions; the tests do not show universal policy bypass.

Record

Document
Nested APP Authentication — Undocumented Risk and Conditional Access Bypass (Talk-page copy)
Researcher
Shang-De Jiang and Jun Sheng Shi
Published by
TROOPERS
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Shang-De Jiang and Jun Sheng Shi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .