Three kinds of things, none of them usable as a credential if leaked: sealed face tokens the platform cannot decrypt, the public halves of device keys (the private halves never leave your phone's secure hardware), and standard directory data your organization provisions (name, email, roles). Administrative credentials like console passwords, client secrets and SCIM tokens are stored hashed. A leaked database yields nothing an attacker can present as a credential.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article