Traditional access models assume:
- Users are trustworthy once authenticated
- Devices are safe if they are inside the network
- Risk does not change during a session
Attackers exploit these assumptions by:
- Stealing credentials
- Reusing valid sessions and tokens
- Logging in from new locations or devices
- Blending into normal activity
Conditional, risk-based access removes these assumptions.


