Session
Entra ID Attack & Defense - Insights and learnings from the playbook project
Over the past six years, a group of community members has built the Entra ID Attack & Defense Playbook: an open-source, MITRE ATT&CK-aligned resource elaborating real-world identity threats on Microsoft Entra and pairing them with mitigation and detection strategies.
In this deep-dive session, we are skipping the high-level basics and going straight into the insights from our learnings. We will share the findings from the research and investigation of the playbook contributors.
We will walk you through the most critical attack paths, including:
- Adversary-in-the-Middle (AiTM) & Token Replay: How attackers steal and abuse Primary Refresh Tokens (PRTs) on Windows devices, and how to detect and contain the threat.
- On-prem to cloud privilege escalation: Weaponizing Microsoft Entra Connect Sync for high-impact lateral movement.
- Targeting Non-Human & Agentic AI Identities: Demonstrating how established attack techniques are repurposed against traditional machine identities, alongside emerging vectors specifically engineered to exploit Agentic AI integrated within Microsoft Entra.
- Proactive Posture Management: Using the Entra ID Security Config Analyzer (EIDSCA) to surface vulnerabilities before they are exploited.
You will leave this session with actionable mitigation strategies, ready-to-use KQL queries for Microsoft Sentinel and Defender, and a clear understanding of where native capabilities shine and where your custom detections need to fill the gaps.
If you are a cloud architect, security engineer, or Entra administrator, this session gives you the insights to shut down these attack paths before they're exploited.
Sami Lamppu
Principal Cloud Security Lead | Microsoft Security MVP | Elisa
Kauniainen, Finland
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top