“Titan validated the contents of the JWT (tenant, audience, app ID, user) but never verified the signature, the most important part of any authentication check.”
Microsoft’s internal analytics platform checked every field on the login token except the signature. The signature is the only part that proves who sent it. A 16-year-old with an AI hackbot turned that into admin access across 9,863 tables and 17.3 trillion rows. Microsoft paid him $5,000.