Golden SAML attack
Forging SAML assertions with an identity provider's stolen signing key, so an attacker can sign in to services that trust that key as any user they choose, bypassing the provider's login.
A golden SAML attack targets the trust at the centre of SAML federation. A service provider accepts an assertion because it carries a valid signature from the identity provider it trusts. An attacker who steals the provider’s token-signing private key can create assertions for any user and sign them so that services trusting that key accept them. The name comes from practitioner security research, by analogy with the Kerberos golden ticket attack.
The forged assertion never passes through the identity provider’s login, so passwords and multi-factor authentication are not consulted, and resetting a victim’s password does not stop it because the forgery rests on the signing key. Defences centre on that key: protecting it in a hardware security module where possible, treating the identity provider’s servers as highly privileged systems, and watching for service provider sign-ins with no matching authentication event at the identity provider. After a compromise, the key is replaced and relying parties update their federation metadata.
Exam relevance: a scenario is likely to describe cloud sign-ins with no matching login at the identity provider, or ask why MFA did not stop them. Candidates are expected to recognise a forged SAML assertion, to trace it to a stolen signing key, and to prefer key protection and rotation over password resets.