TL;DR: Remote and hybrid work expand identity attack paths through phishing, VPN credential theft, SaaS OAuth abuse, and shadow IT, and Expel argues that ITDR closes those gaps with behavioral baselines, device fingerprinting, and continuous SaaS monitoring. The deeper issue is that perimeter-era controls still assume identity is stable enough to trust, while distributed work makes trust conditional and constantly testable.
NHIMG editorial — based on content published by Expel: ITDR and remote workforce identity risk
Questions worth separating out
Q: How should security teams reduce identity risk in remote workforce environments?
A: Security teams should reduce the number of resources each remote identity can reach, then align MFA, device posture, and access reviews with how people actually work.
Q: Why does remote work make OAuth abuse more dangerous?
A: Remote work makes OAuth abuse more dangerous because SaaS access becomes the operational backbone, so a compromised grant can move laterally across business apps without a fresh login event.
Q: What breaks when identity monitoring only looks at network location?
A: Network-only monitoring breaks because remote users no longer share a stable office perimeter, and attackers can authenticate from anywhere once credentials are stolen.
Practitioner guidance
- Map remote identity trust assumptions to actual access paths Document where your programme still assumes users are on trusted networks, then compare that assumption with VPN, SaaS, and browser-based access patterns.
- Inventory OAuth grants and app consents across the SaaS estate Pull consent records from your identity provider and SaaS platforms, then identify apps with broad scopes, inactive owners, or no expiry review.
- Tune behavioural baselines per user and role Separate frequent travellers, contractors, and fixed-location staff into different behavioural expectations so impossible travel, device changes, and login timing are judged in context.
What's in the full article
Expel's full article covers the operational detail this post intentionally leaves for the source:
- Specific examples of how ITDR spots phishing, VPN theft, SaaS OAuth abuse, and shadow IT in remote environments.
- Control-by-control comparison of behavioral baselines, impossible travel detection, device fingerprinting, and SaaS monitoring.
- Practical guidance on what response actions can be automated when suspicious identity activity is detected.
- Implementation considerations for organisations running Entra ID, Okta, or hybrid identity environments.
👉 Read Expel's analysis of ITDR for remote and hybrid workforce identity risk →
Remote workforce identity risk: are your controls keeping up?
Explore further