Attackers don't need your password to take control of SharePoint – a single stolen session cookie is enough. The Pass-the-Cookie technique is currently one of the most serious threats to companies using Microsoft 365. How does this attack work, who is at risk, and what can you do to effectively protect your data?
Imagine this scenario: an employee returns from vacation, logs into SharePoint, and a few hours later, someone else—without knowing their password—gains full access to company documents, permission lists, and sensitive data. This is not just a distant theory. A Pass-the-Cookie attack allows cybercriminals to log into SharePoint (and many other services) with the victim's privileges, using only stolen session cookies. Microsoft is aware of this issue but does not classify it as a traditional vulnerability. This means that the responsibility for securing the environment falls directly on IT administrators.
How does a Pass-the-Cookie attack work?
The mechanism is simpler than you might think. When you log into SharePoint Online, the system generates session cookies (such as ESTSAUTHPERSISTENT or SPOIDCRL). These are used to maintain an active session without the need to constantly re-enter your password. By default, these cookies are valid for 8 hours, but their lifespan can be extended based on user activity. The problem arises when someone intercepts these files. At that point, the attacker no longer needs the password for anything.
Session cookies are stored in the browser's memory or on the device's hard drive. If a cybercriminal gains access there via malware, phishing, or simply by stealing physical hardware, they can easily transfer them to their own device. Worse, a user changing their password does not always immediately invalidate an active session. You don't need to be a brilliant hacker to carry out such an attack—you can easily find ready-made open-source tools online, such as Mimikatz or sharpchrome, which automate the extraction of cookies from system memory.
Cybersecurity experts have long warned that stealing session cookies is one of the most effective methods for bypassing security measures. It allows attackers to silently infiltrate systems and gain access to data without triggering alerts related to failed login attempts.
Who is at risk?
The vulnerability primarily affects the SharePoint Online platform, but the Pass-the-Cookie technique also works in other services within the Microsoft 365 ecosystem, including:
- OneDrive for Business,
- Teams,
- Outlook Web App (OWA),
- Azure Portal (if the victim has administrative privileges).
In the case of on-premises SharePoint Server deployments (versions 2016 and 2019), the risk arises when the environment is integrated with Azure AD or operates in a hybrid model. Older, unsupported versions (like SharePoint 2013) use different authentication methods, making them resistant to this specific type of attack, although they carry a range of other risks.
The highest risk applies to:
- Companies that do not use Conditional Access policies or modern, phishing-resistant authentication (e.g., FIDO2).
- Individuals logging into company resources from personal or public devices.
- Organizations that neglect regular employee training on phishing and identity theft.
- Accounts with high privileges (e.g., Global Admin or SharePoint Admin) – compromising them gives the attacker the keys to the entire company.
Why doesn't Microsoft fix this "vulnerability"?
For many, this may come as a surprise: Microsoft does not treat Pass-the-Cookie as a classic security bug. In the official Azure AD documentation, the manufacturer admits that session hijacking is possible, but the existence of cookies is a deliberate mechanism to facilitate work. Instead of patching the system, Microsoft recommends that administrators harden the configuration themselves by:
- Shortening session validity times.
- Implementing Conditional Access policies based on location and trusted IP addresses.
- Disabling the option to remember sessions in the browser (Persistent browser session).
Unfortunately, default settings in many companies remain unchanged. As noted by the authors of the Sekurak portal, default system configurations often prioritize user convenience over rigorous security, which opens the door to potential abuse.
How to secure SharePoint against Pass-the-Cookie?
Since we cannot rely on an automatic patch from the manufacturer, we must take care of security ourselves. Here are the most important steps worth implementing in your organization:
1. Implement Conditional Access
Properly configured Conditional Access policies in Azure AD are the foundation of protection. It is worth focusing on the following areas:
- Sign-in frequency: Shorten the session lifetime (e.g., to 1 hour for sensitive resources).
- Persistent browser session: Disable this option so that the browser does not remember the session after it is closed.
- Location-based access: Block login attempts from unusual geographic locations.
- Device compliance: Allow access to SharePoint only from company-managed devices monitored by systems such as Microsoft Defender for Endpoint.
2. Enforce phishing-resistant MFA
Classic two-factor methods (like SMS codes or push notifications) will not help if an attacker has already stolen an active session cookie. To prevent this, you should implement solutions that strongly bind the session to a physical device:
- Hardware keys compliant with the FIDO2 standard (e.g., YubiKey).
- Biometric authentication using Windows Hello for Business.
These methods drastically make it difficult to transfer a session to another, unauthorized device.
3. Monitor suspicious logins
The key to a quick response is constant monitoring of logs in Azure AD Sign-in Logs and SIEM-class systems, such as Microsoft Sentinel. Pay special attention to:
- Logins from new, previously unknown devices.
- Frequent non-interactive logins (Non-interactive sign-in).
- Unusual activity of administrator accounts outside of working hours.
Example analytical query for Microsoft Sentinel:
SigninLogs
| where ClientAppUsed == "Browser"
| where AuthenticationDetails has "Session Cookie"
| where RiskLevel == "high"
4. Educate users
Most infections and leaks start with human negligence. Regular training should cover:
- Recognizing advanced phishing campaigns.
- Prohibiting logins to work systems from private and public computers.
- The habit of manually logging out of SharePoint after finishing work.
- Using private (Incognito) mode when working on shared equipment.
You can read more about how modern social engineering attacks are carried out in our article "Recruitment as a Trojan horse: How hackers infiltrate IT environments via LinkedIn".
5. Invest in malware detection
Password and cookie stealers (so-called infostealers, e.g., RedLine Stealer or Lumma Stealer) are constantly being developed. Modern EDR-class systems are essential for detecting them:
- Microsoft Defender for Endpoint with configured process memory protection.
- Third-party solutions, such as CrowdStrike.
6. Control active sessions
In the admin panel, you have the ability to immediately terminate suspicious sessions. If an anomaly is detected:
- Go to the Azure Active Directory (Microsoft Entra ID) console and navigate to the Users section.
- Select the user's profile and use the Sign out option, which will invalidate all active tokens.
What to do if an incident occurs?
If you suspect that an employee's session cookies have been stolen, act immediately:
- Force sign-out: Terminate all active user sessions in the cloud.
- Reset credentials: Change the victim's password and check if MFA methods on their account have been modified.
- Secure the device: Disconnect the infected computer from the network and scan it (e.g., using Microsoft Defender Offline Scan).
- Report the incident: If the situation requires it, submit a report to CERT Polska.
- Analyze operation history: Review SharePoint Audit Logs to check which files were downloaded or modified during the suspicious session.
Summary: Is SharePoint secure?
SharePoint Online is a secure platform, provided that we do not rely solely on its default configuration. Pass-the-Cookie attacks prove that the traditional approach to passwords and standard MFA is slowly becoming obsolete. To effectively protect company resources, you must:
- Shorten session durations and precisely configure conditional access rules.
- Implement modern hardware-based authentication methods.
- Constantly monitor logs for unusual user behavior.
Cloud security is a continuous process. Ignoring the risks associated with session theft is an open path to losing control over the company's most valuable data.
Sources
- https://sekurak.pl/bez-znajomosci-hasla-mozna-zalogowac-sie-do-sharepointa-jako-admin/
- https://msrc.microsoft.com/update-guide/vulnerability
- https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-session
- https://www.netspi.com/blog/technical/adversary-simulation/pass-the-cookie-attacking-microsoft-365/
- https://www.youtube.com/watch?v=example
- https://www.trustedsec.com/blog/
- https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-session-lifetime
- https://www.mandiant.com/resources/blog
- https://cert.pl/
- https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview
- https://www.huntress.com/blog
- https://www.crowdstrike.com/blog
Comments