Funnel overlay image

If saved passwords can be stolen, valid access becomes real risk

Adam Febery

Security Operations Technical Lead

Published: 10 September 2026

When attackers gain valid access, it’s what happens next that defines the risk. How easily can they move through the environment, avoid detection and turn identity into their route to deeper compromise? And what measures can you take to stop them in their tracks?

You may have noticed that Microsoft has made passkeys the default authentication method in Entra ID. It’s the latest step in a wider shift away from passwords and other phishable sign-in methods in favour of stronger, more resilient authentication.

It’s an important change, but it’s only part of the picture. As organisations make credential-based attacks more difficult, attackers will adapt and seek alternative routes to access. Increasingly, the real challenge is what happens after that point.

Once an attacker gains access to a device, session or credential, they can operate using valid identities and behaviour that appears legitimate.

That’s where much of today’s risk resides, and why modern security design must start with identity.

Why credentials still offer the keys to the kingdom

Credentials remain one of the most valuable assets an attacker can obtain. In most enterprise environments, saved passwords, browser sessions, tokens and accounts are not isolated pieces of data. They are routes into systems, cloud services, internal applications, third-party platforms and shared resources.

If an attacker can extract or misuse those credentials from a compromised device, they may be able to move laterally using access that appears legitimate. To many systems, a valid username and passwords still looks like a valid user.

In practise, that could mean:

  • Moving between cloud services without triggering obvious perimeter alerts
  • Escalating access where privileges are excessive or poorly governed
  • Using compromised accounts to target colleagues, suppliers or customers
  • Extending dwell time because the activity resembles normal user behaviour

The value of a credential has never been the credential itself. It is the access, trust and permissions that come with it. Once those are compromised, attackers can often operate in ways that blend into normal activity.

Stronger authentication changes attacker behaviour

Passkeys and other phishing-resistant authentication methods make many traditional routes to identity compromise significantly harder.

But they don’t remove the risk altogether.

Attackers adapt, turning their efforts to alternative approaches such as:

  • Social engineering
  • Account recovery processes
  • Authentication enrolment
  • Active session
  • Excessive privileges

The objective, however, remains the same: gaining access that appears legitimate.

That creates a challenge for defenders. When an attacker is operating with what appears to be legitimate access, traditional indicators are often absent. Verifying identity at sign-in is only part of the answer. Organisations also need to assess whether access remains appropriate, identify suspicious behaviour quickly and respond when risk emerges.

A sign-in from a managed device in a familiar location may proceed uninterrupted. A sign-in associated with an unfamiliar location, risky device, impossible travel pattern or unusual session may warrant additional verification, restricted access or automatic blocking. Access controls become responsive to context rather than being applied uniformly to every user and every request.

The same principle applies after authentication. Signals such as user behaviour, device state, location and resource access can all contribute to an ongoing assessment of risk, helping organisations identify suspicious activity even when access initially appeared legitimate.

Conditional Access policies, Continuous Access Evaluation (CAE), and Identity Protection support these decisions by evaluating context and risk in real time. Rather than treating authentication as a one-time event, organisations can continually assess trust and adjust access when circumstances change.

Adopting the Zero Trust ‘assume breach’ stance

This continual threat evaluation is core to enabling a Zero Trust stragegy bound by the principles of ‘never trust, always verify.’

Get Zero Trust right and the risks look very different:

Ebony and green file padlock icon on transparent background

Least privilege limits the blast radius

Users and accounts only carry the access they need, reducing how far an attacker can move.

Ebony and green tick shield and globe icon on transparent background

Conditional access applies controls dynamically

Access decisions respond to context, device posture, user risk, location, session behaviour and application sensitivity.

Ebony fingerprint icon on transparent background

Phishing-resistant authentication reduces identity compromise

As organisations adopt passkeys and other phishing-resistant authentication methods, it becomes harder for attackers to turn stolen information into legitimate access.

Continuous monitoring detects suspicious behaviour

Identity risk signals help surface compromise earlier, giving security teams more time to investigate unusual activity and contain threats before they spread.

Automated response contain threats faster

Risk signals can trigger step-up verification, session revocation, access restriction or account protection workflows.

Ebony and green open laptop icon on transparent background

Avoid browser-stored passwords where possible

Encourage password managers, passkeys and stronger sign-in methods that reduce reliance on saved browser credentials.

In other words, Zero Trust does not assume that credentials are always safe because user passed authentication once. It continuously asks whether that access still makes sense.

That matters because attackers move quickly. If identity signals are disconnected from response, suspicious activity may be detected too late or not acted on decisively enough. But when identity, access and security operations are integrated, organisations can shrink the window between compromise, detection and containment.

The takeaways

The reality is that security incidents often unfold through legitimate access.

Attackers don’t always need to break systems in obvious ways. Sometimes they use what the environment already gives them.

That is why we treat identity as the foundation point beneath every layer of your security controls.

The organisations best placed to manged this risk are those who can answer three questions clearly:

  1. Who has access?
  2. Should they still have it?
  3. How quickly are we able to detect and respond to abuse?

If the answer to any of those is unclear, the risk is already there.

Ready to strengthen your identity security?

As a leading Microsoft partner for over 20 years, Kocho helps organisations design and deliver identity security strategies that reduce risk without slowing users down.

Arrange a short call with on of Kocho’s identity experts to find out how we can help.

*PC Mag | Microsoft Edge Password Storage

tag icon

Microsoft Entra e-Guide

Secure access with Microsoft Entra

Learn how Microsoft Entra enables Zero Trust access using passwordless authentication, Conditional Access, and identity‑driven network controls.

Discover how you can:

  • Replace passwords with phishing‑resistant authentication
  • Apply Conditional Access to enforce Zero Trust access decisions
  • Secure private app access without VPN‑based trust
  • Evaluate session risk in real time
  • Reduce identity attack surface
Butterfly overlay image

Author

Adam Febery

Security Operations Technical Lead

With expertise in SecOps, Microsoft Sentinel, Microsoft XDR, KQL, and PowerShell, Adam has a proven track record in leading cross-functional security teams and delivering advanced security solutions.

tag icon

Become Greater

Keep one step ahead of the cyber attackers

Sign up to the Kocho newsletter to get exclusive news, the latest threat reports, Microsoft tech updates, and expert analysis from our cybersecurity specialists.

Plus invites to webinars and industry events.