Identity federation is the backbone of modern enterprise access management. Organisations rely on SAML, OIDC, and OAuth 2.0 trust relationships to enable single sign-on across SaaS platforms, partner networks, and multi-cloud environments. Each federated trust boundary represents an implicit assumption about the security posture of the identity provider on the other side. When those assumptions are violated, an attacker who compromises a single identity in one trust domain can propagate access across every federated boundary that trusts it. This article deconstructs a real-world attack chain, anonymised and reconstructed from a Kryvasis engagement, that exploited exactly this pattern.
The Attack Path: Four Hops, Three Trust Domains
The initial compromise occurred at a third-party SaaS vendor whose IdP was protected by SMS-based MFA. The attacker conducted a SIM-swapping attack against a vendor administrator, obtaining a session token with full administrative privileges. From the vendor's IdP, the attacker enumerated outbound SAML trust relationships and discovered a federation with the target organisation's development environment. The attacker impersonated the vendor administrator to establish a new SAML assertion for a development account, bypassing the target organisation's stricter authentication policies because the federated trust relationship accepted the vendor IdP's assertion without re-authentication. From the development environment, the attacker escalated privileges by exploiting a CI/CD pipeline with stored cloud credentials, obtaining read access to the production environment's configuration store. The fourth hop exploited a cross-account federation between the production environment and the centralised identity platform, providing the attacker with access to the organisation's primary IdP and, consequently, to every downstream application.
Misconfigured Trust Boundaries
The attack succeeded not because of any single vulnerability but because of systematic trust boundary misconfigurations across multiple federation layers. The vendor IdP accepted SMS MFA without enforcing stronger factors for administrative sessions. The SAML trust relationship between the vendor and the target organisation was configured with permissive audience restrictions, accepting assertions for any user in the vendor's IdP rather than specific service accounts. The development environment's federation policy accepted SAML assertions without requiring step-up authentication for privileged operations. Each of these misconfigurations was individually documented in audit reports but was treated as a low-severity finding because it existed within a context of assumed trust. The attack chain was only visible when the trust relationships were evaluated as a continuous path rather than as isolated bilateral configurations.
Detection and Prevention
Detecting cross-boundary federation attacks requires telemetry that spans all federated trust domains. Most security operations centres monitor each identity provider independently, lacking the correlation capability to identify anomalous assertion patterns across trust boundaries. Effective detection strategies include monitoring for SAML assertion anomalies such as unusual audience values, unexpected authentication context changes, and assertion issuance from IdPs that have not been previously active for a given user. Prevention requires enterprise architects to treat federated trust relationships as a single interconnected system rather than as a collection of independent integrations. Every trust boundary should enforce the principle of least privilege, requiring explicit audience restrictions, enforcing strong authentication factors proportional to the access being granted, and implementing continuous session validation rather than relying on initial assertion authentication.
The lesson from this engagement is unambiguous: federated identity is a force multiplier for both operational efficiency and adversarial lateral movement. Organisations that map, monitor, and constrain their trust relationships with the same rigour they apply to network segmentation will contain the blast radius of identity-based attacks. Those that treat federation as a convenience feature will discover that it has become their most consequential attack surface.