SSO, IdP, or federation compromise
Golden SAML
Also called: federation trust abuse
Golden SAML is an attack in which someone who has stolen an identity provider's token-signing key forges SAML authentication tokens. Every app that trusts that identity provider accepts the forged tokens, so the attacker can sign in as any user, with any privileges, without passwords or MFA, and without touching the real login service.
How it works
The attacker first gains administrative access to the federation server, such as on-premises AD FS, and exports its token-signing certificate. With it they create tokens that claim to be any user. Because the tokens are correctly signed, cloud apps accept them, and the activity can bypass logs on the identity provider itself.
A real example
CISA's advisory on post-compromise activity in Microsoft cloud environments described threat actors forging authentication tokens to access resources that trust an on-premises identity provider, in attacks often referred to as Golden SAML.
Source: Detecting Post-Compromise Threat Activity in Microsoft Cloud Environments (AA21-008A) — Cybersecurity and Infrastructure Security Agency (CISA), 2021-01-08
How to stop it
Treat federation servers and their signing keys as top-tier assets, store keys in hardware, limit who can administer them, and watch cloud sign-ins for tokens the identity provider never issued.
Related terms
Sources
- Detecting Post-Compromise Threat Activity in Microsoft Cloud Environments (AA21-008A) — Cybersecurity and Infrastructure Security Agency (CISA), 2021-01-08
Last reviewed Oct 2, 2026