Token Theft in 2026: What CAE and DBSC Actually Cover, and What Your SIEM Still Has to Catch
Continuous Access Evaluation and Device Bound Session Credentials closed some of the AitM gap, but session token theft against Entra ID is still the dominant identity attack and most of the detection burden still falls on the SOC. Here is the shape of the problem and where the first round of tuning has to land.