OAuth Flows in Entra ID: Fundamentals You Thought You Knew
Wednesday 10 February 2027, 11:30–12:30
Speakers
- Christopher Brumm
- Fabian Bader
About this session
OAuth 2.0 and OpenID Connect are the foundation of every authentication and authorization decision Entra ID makes – yet which flows are actually still in use, what artifacts like tokens and credentials they produce, and where the real risk sits are details even people who work with Entra ID daily tend to get fuzzy on. In this session we take a genuinely deep look at these fundamentals: which flows exist and which ones you'll actually encounter in Entra ID today versus which are effectively legacy, what happens to tokens and credentials at each step, and why getting this "basic" mental model wrong is exactly what makes so many real-world attacks possible in the first place. We'll also cover which flows should make your alarm bells go off and the classes of attacks they enable – enough protocol-level detail to satisfy identity experts, without turning this into a dedicated attack showcase. Whether you're new to Entra ID or have been doing this for years, expect to leave with a sharper mental model of what's actually happening under the hood.