Burp Suite User Forum

Create new post

Authorisation in SSO

The | Last updated: Mar 15, 2024 11:29AM UTC

The application I am testing uses SSO login.microsoftonline.com. Once logged in, of course I can manually manage the token that appeared in my request history, but I would like this token to also be applied to the automatic scans that burp professional offers. How can I make it so that each new automatic scan is configured to authorise successfully?

Hannah, PortSwigger Agent | Last updated: Mar 15, 2024 05:32PM UTC

Hi As part of your Scan, have you tried providing a recorded login sequence? You can find our documentation on recorded login sequences here: https://portswigger.net/burp/documentation/scanner/authenticated-scanning/recorded-login-sequences

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.