Federal Guidance Targets Cloud Token Attacks
New recommendations address token theft, forgery and misuse across cloud identity, single sign-on and application access systems.
- By Chelsey Arries
- Sep 15, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) and National Institute of Standards and Technology (NIST) have released final guidance for protecting cloud identity tokens and assertions from theft, forgery and misuse.
Interagency Report 8587 provides federal agencies and cloud service providers with recommendations for securing the digital credentials used by single sign-on systems, identity federation and application programming interfaces.
Attackers can steal or forge tokens to impersonate authorized users, move laterally through enterprise networks and access sensitive information. Unlike passwords, tokens may provide access to several connected applications after a user has been authenticated.
The report outlines architectural considerations for identity providers and authorization servers. It also recommends stronger key management, token verification and token life cycle controls.
Additional guidance covers digitally signed and asymmetrically encrypted tokens used for single sign-on, federation and API access. The report calls for configurable, transparent and interoperable controls that organizations can adjust based on risk and emerging threats.
The recommendations expand on the identity and access management controls in NIST Special Publication 800-53. They apply to commercial cloud services and government-operated cloud environments.
CISA and NIST received nearly 250 public comments while developing the final report. The agencies also consulted cloud and identity technology organizations about token validation, secrets management and threat detection.
About the Author
Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.