Somewhere right now, an attacker is logged into a real employee account. They didn’t use a password to do it, and they didn’t even have to defeat MFA. They used a session cookie they found or bought on the darknet.
That doesn’t sit well with us. Not on our watch. Which is why…
Available today: SpyCloud Identity Guardians for Entra ID and Okta Workforce now detect and remediate exposed sessions, not just exposed passwords.
TL;DR
- Session hijacking prevention is now a core pillar of identity threat protection, not a nice-to-have. A password reset does nothing to protect a compromised session an attacker is already using.
-
Full on-prem, hybrid, and cloud coverage: Whatever mix of Entra ID, Okta Workforce, and on-prem Active Directory you're running, SpyCloud has you covered for credentials and sessions, wherever they apply.
- Active Directory Guardian still does the heavy lifting for your on-prem directories. Scroll to the bottom of this blog for details.
- New severity tier alert: SpyCloud now flags exposure records as Access, a level above Critical, when stolen data includes an active session or token.
You may ask yourself, what’s an Identity Guardian? So here’s some quick context if this is your first time here.
Identity Guardians are SpyCloud’s automated remediation products that work with/support your existing identity infrastructure. They continuously monitor recaptured identity data for your entire workforce, then automatically fix what’s exposed – doing everything from alerting users, to resetting compromised passwords and revoking compromised sessions, directly inside your IdP of choice. There is no manual triage required, unless you want it.
Attackers stopped needing a password. Did your enterprise identity strategy notice?
As Trevor Hilligoss, SpyCloud’s Chief Intelligence Officer, said in our 2026 Phishing Pulse Report, “AI-generated lures, phishing-as-a-service, and adversary-in-the-middle techniques are helping attackers walk away with authenticated access that can outlast a password reset.”
Data from that same report shows that phishing attacks are now roughly five times more likely to target enterprise users than malware infections. And the attackers behind that shift aren’t stealing passwords so much as they’re stealing what happens after a user types it. Cookies. Refresh tokens. The stuff that keeps a user logged in so they don’t have to re-authenticate every ten minutes.
Translation: you can rotate a password all day. If the attacker’s holding a live session, they’re already inside, and your reset doesn’t kick them out.
This is why we aren’t treating session exposure as a footnote to credential exposure. It’s the other half of identity threat protection, not a nice-to-have bolted onto it. Identity Guardians already handled the password half of that equation automatically. Starting today, they handle the session half, too.
SpyCloud Identity Guardians don’t treat passwords and sessions as separate identity security problems
| Session compromise | Credential exposure | |
|---|---|---|
| What's stolen? | Session cookies, refresh tokens, authentication artifacts | Username and passwords |
| How does it get stolen? | PhaaS kits, infostealer malware | Third-party breaches, combolists, malware, phishing |
| SpyCloud fix | Session and refresh token revocation | Password reset, user notified |
| SpyCloud speed | Automatically, within hours of discovery | Automatically, within 5 minutes (for malware) |
What's live for Entra ID and Okta, and how to take advantage of it
SpyCloud’s Entra ID Guardian and Okta Workforce Guardian now do two jobs at once: they reset exposed passwords the moment a match is confirmed, and they also detect and revoke compromised sessions recaptured from infostealer malware and phishing to close initial access vectors.
If you’re running Okta, Okta Workforce Guardian handles credential remediation plus session revocation, and extends to connected apps wherever you’ve got Universal Logout enabled on your end.
If you’re running Entra ID, Entra ID Guardian covers the same ground: credentials and sessions, cloud-native, and nothing to install.
How SpyCloud Identity Guardian kills stolen sessions, dead
Follow this guided demo to see how Identity Guardians work within the SpyCloud console.
Detect it. SpyCloud Identity Guardians continuously monitor for exposed identity data matching your extended workforce, from employees to contractors, with new data published continuously
Spot it. An employee’s email or username turns up in a phishing or malware record and that record’s carrying stolen session data, not just a password.
Confirm it. This is an identity match, not a token check. SpyCloud confirms the access is compromised, not just exposed, validated by criminal chatter showing the session or token was actually used.
Kill it. The session automatically gets revoked at the identity provider before the attacker gets to use it again.
It’s your call: Hands-on control or hands-off automation. Manually revoke sessions and refresh tokens, or set exclusion rules and timing to handle it automatically via your IdP.
Log it. Every action is logged for audit and NIST 800-63B-aligned compliance documentation.
Running both, plus on-prem Active Directory? That’s most enterprises, and it’s exactly what this was built for. Active Directory Guardian doesn’t detect sessions on its own, but when it resets a compromised password, it can also trigger Okta or Entra ID to revoke that user’s active sessions downstream.
Pair Active Directory Guardian for your on-prem credential coverage with Entra ID Guardian and/or Okta Workforce Guardian for cloud credential and session coverage, all under one policy.
New: Exposure data just got a severity upgrade
We just hit one trillion recaptured identity records in our data lake, and to align with the developing threat landscape, SpyCloud now publishes exposure records with a new severity tier above Critical: Access. Why? Because not every exposure deserves the same 2AM phone call, but some do.
It’s reserved for exactly what it sounds like – live session and token data stolen through phishing or malware, the kind of exposure where an attacker doesn’t need to log in because they’re already authenticated. When you see Access-level data within SpyCloud, treat it as “this door is open right now,” not “this door might get picked eventually.”
Luckily, Identity Guardians will automatically detect and remediate these exposures directly within your IdP.
Research Agent handles the mechanics for you. The investigative methodology encoded in the agent is built from the same tradecraft senior analysts use successfully. The difference is that running those pivots now happens automatically, in seconds.
Now surfacing directly in your SpyCloud environment: When you see an Access record, the playbook changes so you can reset the session, not just the password.
The callout you scrolled down for: Active Directory Guardian is still relevant – and quietly incredible
Everyone’s talking about session revocation, and rightfully so. But if you’re running an on-prem or hybrid Active Directory domain, don’t let Active Directory Guardian get lost in the noise, because what it does is genuinely hard to find anywhere else:
- It leverages SpyCloud’s holistic identity matching capability to find up to 14x more exposed passwords than exact-match scanning alone by correlating an employee's corporate identity against their personal digital footprint. Password reuse doesn't respect the line between your work account and someone's personal Netflix login, so Active Directory Guardian doesn't either.
- It uses fuzzy matching to test up to 1,000 variations of every exposed password, catching the "just changed the last character" trick that exact-match tools miss every time.
- Its password filtering blocks weak or previously exposed passwords the moment someone tries to set them, before they ever become active, not after.
- It remediates high-risk NHI threats, specifically credential reuse across service accounts and non-federated accounts, a critical attack surface often overlooked by standard security tools.
If you’ve got an AD domain and you’re not running this, you’re leaving 14x the exposure on the table and finding out about weak passwords after they’re already set instead of before.
Follow this guided demo to see how Active Directory Guardian works within the SpyCloud console.
Bottom line: Now is a good time for automated account takeover and session hijacking prevention
Identity-based threats have moved beyond the password – so our automated identity threat protection does too.
Entra ID Guardian and Okta Workforce Guardian now close the gap opened by session threats alongside the credential gap and it’s available now, with severity data that tells you which exposures need attention first.
SpyCloud customers with an active Workforce Threat Protection license can start detecting or remediating exposed sessions and refresh tokens today.
Discover what cybercriminals already have in hand – and prevent targeted attacks with SpyCloud.
FAQs
Session hijacking occurs when attackers steal active session cookies or tokens through phishing or malware, allowing them to access accounts without needing passwords. SpyCloud Identity Guardians automatically detect and revoke these compromised sessions within hours of discovery, directly inside your identity provider.
Password resets change login credentials but don’t terminate active sessions, meaning attackers with stolen session tokens remain logged in. Session revocation immediately terminates the authenticated session and refresh token at the identity provider level, kicking the attacker out regardless of whether they have the password.
“Access” is a severity level that sits above “Critical” in priority and flags exposure records containing verified, compromised session data or tokens stolen through phishing or malware. This designation, validated by criminal chatter, indicates an attacker has authenticated access right now, not just the potential to gain access later.
Active Directory Guardian uses fuzzy matching to test up to 1,000 password variations and correlates corporate identities against personal digital footprints, finding up to 14x more exposed passwords than exact-match scanning tools that only check for identical password strings.