Session

Entra ID Attack & Defense

Identity is the new perimeter — and attackers know it. Over the past four years, a community of security researchers has built and continuously expanded the Entra ID Attack & Defense Playbook: an open, structured, and MITRE ATT&CK-aligned resource that dissects real-world attack scenarios against Microsoft Entra ID and pairs each one with practical detection and mitigation guidance using the Microsoft security stack.

In this deep-dive session, we share the story behind the project: how a geographically distributed team collaborated almost entirely remotely, running attack simulations, building KQL detections, and stress-testing findings across hundreds of lab iterations — all as a community effort outside of regular working hours.

We'll walk you through the playbook's most critical scenarios, including:
- Adversary-in-the-Middle (AiTM) phishing attacks and replay of token artifacts on Windows devices — how attackers steal and abuse them, and how to detect and contain the threat
- Privilege escalation via Microsoft Entra Connect Sync - a high-impact lateral movement path from on-premises AD to the cloud
- Illicit Consent Grant and OAuth phishing - how attackers weaponize registered applications to silently harvest data
- Entra ID Security Config Analyzer (EIDSCA) - proactive posture management to surface weak configurations before attackers exploit them

For every scenario, you'll leave with actionable mitigation strategies, ready-to-use KQL detection queries, and a clear understanding of where native Microsoft Defender and Sentinel capabilities cover you - and where custom detections fill the gap.

Whether you're an identity architect, security engineer, or SOC analyst, this session gives you the playbook of the adversary so you can build a stronger defense.

Sami Lamppu

Principal Cloud Security Lead | Microsoft Security MVP | Elisa

Kauniainen, Finland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top