Preliminary research
Nested APP Authentication — Undocumented Risk and Conditional Access Bypass
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
Conference page for a study of Microsoft Nested App Authentication. The associated presentation varies broker, nested-client and resource identities and compares Conditional Access inclusion and exclusion policies. Exploitation assumes a usable refresh token and delegated permissions; the tests do not show universal policy bypass.
Record
- Researcher
- Shang-De Jiang and Jun Sheng Shi
- Published by
- TROOPERS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Shang-De Jiang and Jun Sheng Shi, first published at the original source. Preserved copies are kept so the citation survives its host.