When attackers gain valid access, it’s what happens next that defines the risk. How easily can they move through the environment, avoid detection and turn identity into their route to deeper compromise? And what measures can you take to stop them in their tracks?
You may have noticed that Microsoft has made passkeys the default authentication method in Entra ID. It’s the latest step in a wider shift away from passwords and other phishable sign-in methods in favour of stronger, more resilient authentication.
It’s an important change, but it’s only part of the picture. As organisations make credential-based attacks more difficult, attackers will adapt and seek alternative routes to access. Increasingly, the real challenge is what happens after that point.
Once an attacker gains access to a device, session or credential, they can operate using valid identities and behaviour that appears legitimate.
That’s where much of today’s risk resides, and why modern security design must start with identity.
Why credentials still offer the keys to the kingdom
Credentials remain one of the most valuable assets an attacker can obtain. In most enterprise environments, saved passwords, browser sessions, tokens and accounts are not isolated pieces of data. They are routes into systems, cloud services, internal applications, third-party platforms and shared resources.
If an attacker can extract or misuse those credentials from a compromised device, they may be able to move laterally using access that appears legitimate. To many systems, a valid username and passwords still looks like a valid user.
In practise, that could mean:
- Moving between cloud services without triggering obvious perimeter alerts
- Escalating access where privileges are excessive or poorly governed
- Using compromised accounts to target colleagues, suppliers or customers
- Extending dwell time because the activity resembles normal user behaviour
The value of a credential has never been the credential itself. It is the access, trust and permissions that come with it. Once those are compromised, attackers can often operate in ways that blend into normal activity.
Stronger authentication changes attacker behaviour
Passkeys and other phishing-resistant authentication methods make many traditional routes to identity compromise significantly harder.
But they don’t remove the risk altogether.
Attackers adapt, turning their efforts to alternative approaches such as:
- Social engineering
- Account recovery processes
- Authentication enrolment
- Active session
- Excessive privileges
The objective, however, remains the same: gaining access that appears legitimate.
That creates a challenge for defenders. When an attacker is operating with what appears to be legitimate access, traditional indicators are often absent. Verifying identity at sign-in is only part of the answer. Organisations also need to assess whether access remains appropriate, identify suspicious behaviour quickly and respond when risk emerges.
A sign-in from a managed device in a familiar location may proceed uninterrupted. A sign-in associated with an unfamiliar location, risky device, impossible travel pattern or unusual session may warrant additional verification, restricted access or automatic blocking. Access controls become responsive to context rather than being applied uniformly to every user and every request.
The same principle applies after authentication. Signals such as user behaviour, device state, location and resource access can all contribute to an ongoing assessment of risk, helping organisations identify suspicious activity even when access initially appeared legitimate.
Conditional Access policies, Continuous Access Evaluation (CAE), and Identity Protection support these decisions by evaluating context and risk in real time. Rather than treating authentication as a one-time event, organisations can continually assess trust and adjust access when circumstances change.
Adopting the Zero Trust ‘assume breach’ stance
This continual threat evaluation is core to enabling a Zero Trust stragegy bound by the principles of ‘never trust, always verify.’
Get Zero Trust right and the risks look very different:
In other words, Zero Trust does not assume that credentials are always safe because user passed authentication once. It continuously asks whether that access still makes sense.
That matters because attackers move quickly. If identity signals are disconnected from response, suspicious activity may be detected too late or not acted on decisively enough. But when identity, access and security operations are integrated, organisations can shrink the window between compromise, detection and containment.
The takeaways
The reality is that security incidents often unfold through legitimate access.
Attackers don’t always need to break systems in obvious ways. Sometimes they use what the environment already gives them.
That is why we treat identity as the foundation point beneath every layer of your security controls.
The organisations best placed to manged this risk are those who can answer three questions clearly:
- Who has access?
- Should they still have it?
- How quickly are we able to detect and respond to abuse?
If the answer to any of those is unclear, the risk is already there.
Ready to strengthen your identity security?
As a leading Microsoft partner for over 20 years, Kocho helps organisations design and deliver identity security strategies that reduce risk without slowing users down.
Arrange a short call with on of Kocho’s identity experts to find out how we can help.
Microsoft Entra e-Guide
Secure access with Microsoft Entra
Learn how Microsoft Entra enables Zero Trust access using passwordless authentication, Conditional Access, and identity‑driven network controls.
Discover how you can:
- Replace passwords with phishing‑resistant authentication
- Apply Conditional Access to enforce Zero Trust access decisions
- Secure private app access without VPN‑based trust
- Evaluate session risk in real time
- Reduce identity attack surface
Become Greater
Keep one step ahead of the cyber attackers
Sign up to the Kocho newsletter to get exclusive news, the latest threat reports, Microsoft tech updates, and expert analysis from our cybersecurity specialists.
Plus invites to webinars and industry events.