While password spray and MFA phishing are commodity attacks against users, we continue to see interesting, advanced attack scenarios that catch the news, many times with the victim company left in a tough situation. But with each attack, the questions that come up with the news hype cycle - are we vulnerable? Has Microsoft fixed this? What’s the complexity and likelihood? - they all quickly go to the sidelines as business must continue. In this session we’ll explore the state of the more recent advanced identity attacks in Entra ID. We won’t just talk about them, but with a red and blue lens, we’ll examine the state of each attack scenario, covering research on how viable these attacks still are. For the attacks that are no longer possible, we’ll explore the fix from Microsoft and examine whether things are truly resolved. For the attacks that are still viable, we’ll deep dive into how they work, and give actionable advice to defenders to protect the organization from them.
In the case the session is being reviewed anonymized, we don’t want to reveal who we are but to lend more depth the co-presenters have strong red and blue backgrounds - one working in security research around Entra and the other working to provide managed SOC services to customers. With this we think it will lend to the session having a strong lens from both sides. Also we really look forward to presenting at WP Ninjas this year and appreciate the time taken to review this.
I am a big fan of Microsoft Cloud Security products because there my two favorite topics Identity and Security work together in a unique way. I've been working in IT for quite a while and have almost 20 years of experience in IT security in various roles. At the moment I am a Cybersecurity Architect at glueckkanja AG and help our customers with my favorite topics. I live with my family in Hamburg.