Yet another reason why Token Exchange is dangerous π€―π±
"Bing is allowed to issue Office tokens for any logged-on user"
https://twitter.com/hillai/status/1641146523990753290
WeChat ID
aaronpk_tv
@aaronpk Interesting find.
Does this mean RFC 8693: Token Exchange is by its very nature dangerous? What would be a better way?