[weglot_switcher]
SpyCloud logo with network lines and text 'Identity Guardians'.

How to Detect and Remediate Stolen Sessions Automatically with Your IdP + SpyCloud

Table of Contents

Check your exposure

Somewhere right now, an attacker is logged into a real employee account. They didn’t use a password to do it, and they didn’t even have to defeat MFA. They used a session cookie they found or bought on the darknet.

That doesn’t sit well with us. Not on our watch. Which is why…

Available today: SpyCloud Identity Guardians for Entra ID and Okta Workforce now detect and remediate exposed sessions, not just exposed passwords.

TL;DR

You may ask yourself, what’s an Identity Guardian? So here’s some quick context if this is your first time here.

Identity Guardians are SpyCloud’s automated remediation products that work with/support your existing identity infrastructure. They continuously monitor recaptured identity data for your entire workforce, then automatically fix what’s exposed – doing everything from alerting users, to resetting compromised passwords and revoking compromised sessions, directly inside your IdP of choice. There is no manual triage required, unless you want it.

Attackers stopped needing a password. Did your enterprise identity strategy notice?

As Trevor Hilligoss, SpyCloud’s Chief Intelligence Officer, said in our 2026 Phishing Pulse Report, “AI-generated lures, phishing-as-a-service, and adversary-in-the-middle techniques are helping attackers walk away with authenticated access that can outlast a password reset.”

Data from that same report shows that phishing attacks are now roughly five times more likely to target enterprise users than malware infections. And the attackers behind that shift aren’t stealing passwords so much as they’re stealing what happens after a user types it. Cookies. Refresh tokens. The stuff that keeps a user logged in so they don’t have to re-authenticate every ten minutes.

Translation: you can rotate a password all day. If the attacker’s holding a live session, they’re already inside, and your reset doesn’t kick them out.

This is why we aren’t treating session exposure as a footnote to credential exposure. It’s the other half of identity threat protection, not a nice-to-have bolted onto it. Identity Guardians already handled the password half of that equation automatically. Starting today, they handle the session half, too.

SpyCloud Identity Guardians don’t treat passwords and sessions as separate identity security problems
Session compromise Credential exposure
What's stolen? Session cookies, refresh tokens, authentication artifacts Username and passwords
How does it get stolen? PhaaS kits, infostealer malware Third-party breaches, combolists, malware, phishing
SpyCloud fix Session and refresh token revocation Password reset, user notified
SpyCloud speed Automatically, within hours of discovery Automatically, within 5 minutes (for malware)

What's live for Entra ID and Okta, and how to take advantage of it

SpyCloud’s Entra ID Guardian and Okta Workforce Guardian now do two jobs at once: they reset exposed passwords the moment a match is confirmed, and they also detect and revoke compromised sessions recaptured from infostealer malware and phishing to close initial access vectors.

If you’re running Okta, Okta Workforce Guardian handles credential remediation plus session revocation, and extends to connected apps wherever you’ve got Universal Logout enabled on your end.  

If you’re running Entra ID, Entra ID Guardian covers the same ground: credentials and sessions, cloud-native, and nothing to install.

How SpyCloud Identity Guardian kills stolen sessions, dead

     
       
  

Follow this guided demo to see how Identity Guardians work within the SpyCloud console.

Detect it. SpyCloud Identity Guardians continuously monitor for exposed identity data matching your extended workforce, from employees to contractors, with new data published continuously

Spot it. An employee’s email or username turns up in a phishing or malware record and that record’s carrying stolen session data, not just a password.

Confirm it. This is an identity match, not a token check. SpyCloud confirms the access is compromised, not just exposed, validated by criminal chatter showing the session or token was actually used.

Kill it. The session automatically gets revoked at the identity provider before the attacker gets to use it again.

Screenshot of SpyCloud session revocation process for stolen session detection.

It’s your call: Hands-on control or hands-off automation. Manually revoke sessions and refresh tokens, or set exclusion rules and timing to handle it automatically via your IdP.

Log it. Every action is logged for audit and NIST 800-63B-aligned compliance documentation.

Running both, plus on-prem Active Directory? That’s most enterprises, and it’s exactly what this was built for. Active Directory Guardian doesn’t detect sessions on its own, but when it resets a compromised password, it can also trigger Okta or Entra ID to revoke that user’s active sessions downstream.

Pair Active Directory Guardian for your on-prem credential coverage with Entra ID Guardian and/or Okta Workforce Guardian for cloud credential and session coverage, all under one policy.

New: Exposure data just got a severity upgrade

We just hit one trillion recaptured identity records in our data lake, and to align with the developing threat landscape, SpyCloud now publishes exposure records with a new severity tier above Critical: Access. Why? Because not every exposure deserves the same 2AM phone call, but some do.

It’s reserved for exactly what it sounds like – live session and token data stolen through phishing or malware, the kind of exposure where an attacker doesn’t need to log in because they’re already authenticated. When you see Access-level data within SpyCloud, treat it as “this door is open right now,” not “this door might get picked eventually.”

Luckily, Identity Guardians will automatically detect and remediate these exposures directly within your IdP.

Research Agent handles the mechanics for you. The investigative methodology encoded in the agent is built from the same tradecraft senior analysts use successfully. The difference is that running those pivots now happens automatically, in seconds.

Now surfacing directly in your SpyCloud environment: When you see an Access record, the playbook changes so you can reset the session, not just the password.

The callout you scrolled down for: Active Directory Guardian is still relevant – and quietly incredible

Everyone’s talking about session revocation, and rightfully so. But if you’re running an on-prem or hybrid Active Directory domain, don’t let Active Directory Guardian get lost in the noise, because what it does is genuinely hard to find anywhere else:

If you’ve got an AD domain and you’re not running this, you’re leaving 14x the exposure on the table and finding out about weak passwords after they’re already set instead of before. 

Follow this guided demo to see how Active Directory Guardian works within the SpyCloud console.

Bottom line: Now is a good time for automated account takeover and session hijacking prevention

Identity-based threats have moved beyond the password – so our automated identity threat protection does too.

Entra ID Guardian and Okta Workforce Guardian now close the gap opened by session threats alongside the credential gap and it’s available now, with severity data that tells you which exposures need attention first.

SpyCloud customers with an active Workforce Threat Protection license can start detecting or remediating exposed sessions and refresh tokens today.

Discover what cybercriminals already have in hand – and prevent targeted attacks with SpyCloud.

FAQs

Session hijacking occurs when attackers steal active session cookies or tokens through phishing or malware, allowing them to access accounts without needing passwords. SpyCloud Identity Guardians automatically detect and revoke these compromised sessions within hours of discovery, directly inside your identity provider.

Password resets change login credentials but don’t terminate active sessions, meaning attackers with stolen session tokens remain logged in. Session revocation immediately terminates the authenticated session and refresh token at the identity provider level, kicking the attacker out regardless of whether they have the password.

Access” is a severity level that sits above “Critical” in priority and flags exposure records containing verified, compromised session data or tokens stolen through phishing or malware. This designation, validated by criminal chatter, indicates an attacker has authenticated access right now, not just the potential to gain access later.

Active Directory Guardian uses fuzzy matching to test up to 1,000 password variations and correlates corporate identities against personal digital footprints, finding up to 14x more exposed passwords than exact-match scanning tools that only check for identical password strings.

Keep reading

Illustration of a research agent with network connections for cybersecurity.
Introducing Research Agent: Your Investigations Team Just Got An Unfair Advantage
SpyCloud’s Research Agent is an agentic investigation tool that plans pivots, correlates identities, and returns finished intelligence grounded in over one trillion recaptured criminal-source assets. Every finding cites a specific verifiable record.
SpyCloud and Okta integration alert for enhanced security monitoring.
SpyCloud + Okta Identity Threat Protection: Closing the Gap Between Identity Exposure and Attack
SpyCloud’s integration with Okta Identity Threat Protection (ITP) levels up your defenses with darknet identity intelligence that automatically remediates exposed identity data, including stolen sessions and tokens. See how it works.
SpyCloud and Ping Identity logo showcasing identity security integration.
SpyCloud + Ping Identity: Holistic Identity Intelligence, Built Into Every Login
SpyCloud’s new partnership with Ping Identity embeds our recaptured darknet identity data directly into PingOne DaVinci & PingOne Advanced Identity Cloud at every identity event.

Check Your Company's Exposure

See your real-time exposure details powered by SpyCloud.

Research Agent is now available: Close cases in minutes with agentic investigations

X