
DEF CON 33 - Mac PRT Cookie Theft & Entra ID Persistence - Shang-De Jiang, Dong-Yi Ye, Tung-lin Lee
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 41:10
Researchers discovered methods to steal PRT cookies on macOS and persist in Microsoft's identity platform, with Microsoft's macOS implementation being more secure than Windows.
Key Takeaways:
• PRT (Primary Refresh Token) represents user identity and session key, allowing attackers to bypass conditional access policies when stolen
• Three methods to steal PRT cookies on macOS: headless browser, bypassing browser core's parent process check, and direct SSO invocation via Apple's API
• PRT cookies only last 15 minutes, requiring persistence techniques for long-term access
• Full attack chain includes password reset without knowing original password, adding new MFA methods, registering fake devices, and bypassing NGC MFA protection
• Microsoft initially dismissed some vulnerabilities but later agreed to implement stronger authentication after seeing the complete attack flow
• Mitigation includes monitoring bundle IDs, checking process signatures, implementing stricter conditional access policies, and creating weak criteria like IP location and user agent checks
The research demonstrates significant security gaps in Microsoft's SSO implementation, particularly on Windows, with implications for enterprise security and zero-trust architectures.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So thanks everyone. Um I'm John. So today we are excited to share about how we steal the PRT cookie on Mac OS and the use the PRT cookie persistent in Android ID. There's a very funny fact is we realize Microsoft implementation on Mac OS for a PR cookie is more security implementation than than on Windows. So I will starting first and I will hand over to Leang speaker. I'm Jang. I'm the director of research at SC and I have a blogger called Heapas Jang and I'm researcher. of course I speak at several conference but it's my first time in devcon. So let's jumping out to desktopic because Microsoft has a lot of different type of service maybe 100 200 and if you don't want our computer asking the password again and again we need to ask our computer single sign on to help us sing sign on to the…