Web Hack List

Preliminary research

Nested APP Authentication — Undocumented Risk and Conditional Access Bypass

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Conference page for a study of Microsoft Nested App Authentication. The associated presentation varies broker, nested-client and resource identities and compares Conditional Access inclusion and exclusion policies. Exploitation assumes a usable refresh token and delegated permissions; the tests do not show universal policy bypass.

Record

Researcher
Shang-De Jiang and Jun Sheng Shi
Published by
TROOPERS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Shang-De Jiang and Jun Sheng Shi, first published at the original source. Preserved copies are kept so the citation survives its host.