A rare, but highly welcome change. Microsoft changed the license requirement for Token protection from Entra ID P2 to P1.
This will protect more customers in the long run and lead to a more secure ecosystem.
learn.microsoft.com/en-us/entra/...
@fabian.bader.cloud
#Security #Azure #EntraID #XDR #MDE #Identity #M365 #AD #PKI #KQL Microsoft MVP Tweets and opinions are my own
A rare, but highly welcome change. Microsoft changed the license requirement for Token protection from Entra ID P2 to P1.
This will protect more customers in the long run and lead to a more secure ecosystem.
learn.microsoft.com/en-us/entra/...
π¨ PSA - Zero day in SharePoint on-prem is actively exploited!
β½ Have Defender AV active
β½ Don't disable AMSI integration of SharePoint
β½ Keep an eye out for the alerts outlined in the article
β½ Look for post exploitation with the hunting query
msrc.microsoft.com/blog/2025/07...
Part 8053 of eleventy billion on our path to killing NTLM: way way way way way better auditing.
support.microsoft.com/en-us/topic/...
What r u doing while cooking?
Thatβs my distraction β¦.
#PSConfEU 2915
The latest on the Azure AD Graph retirement mentions two temporary outage tests and more guidance.
If something stops working it might be because of those tests.
#Entra #AADGraph
techcommunity.microsoft.com/blog/microso...
One of the results of the joined research with @dirkjanm.io is entrascopes.com
Basically the yellow pages for Microsoft first party apps.
#TROOPERS25
"One thing we have learned over years is that the world moves quickly, and building is easy but supporting is hard...."
Sydney Smith 2025
#StateOfTheShell
#PSConfEU 2025
Citrix Netscaler customers - keep calm and patch CVE-2025-5777 from Tuesday.
It allows unauth memory reads, has similarities to CitrixBleed (CVE-2023-4966) as may allow session token theft.
Great company you have there. Enjoy MalmΓΆ
22.06.2025 21:54 β π 0 π 0 π¬ 0 π 0Rerunning my test scenarios for the #TROOPERS25 presentation...
22.06.2025 16:58 β π 4 π 1 π¬ 0 π 0Congratulations π
01.06.2025 22:07 β π 1 π 0 π¬ 0 π 0A margarita pizza with mozzarella cheese
Pizza π
25.05.2025 17:31 β π 2 π 0 π¬ 0 π 0Microsoft trying to be like @vxunderground, smh π
20.05.2025 19:17 β π 4 π 1 π¬ 0 π 0Suspicious domain m365sessionlogin[.]com was registered through Njalla on 5/18/25. Domain itself does not resolve, but subdomains login, logon, and office365 indicate hosting at 80.78.30[.]154.
19.05.2025 13:34 β π 7 π 3 π¬ 1 π 0The unified IdentityInfo table is the most comprehensive way to identify users and their attributes in the unified SOC experience.
You have to onboard your Sentinel workspace AND enable UEBA to take advantage of this in advanced hunting.
#xdr #sentinel
Made it on #58 of the MSRC leaderboard Q1 2025
First time I made it on the @msftsecresponse leaderboard πΎ
msrc.microsoft.com/leaderboard
Experts live NL
Workplace Ninja Norway
TROOPERS (DE)
Workplace Ninja Summit (CH)
Not yet, but if you see me at any of the conferences starting June come over and ask me about it.
07.05.2025 18:37 β π 1 π 0 π¬ 1 π 0a card deck from the back, fanned out, reading "Family of Client IDs" with a tree in the middle
Planning for some days off from work. What to put in the duffle back beside a good book and some sunscreen?
My new favorite card game of course.
#FOCI #FamilyOfClientID
Application Based Authentication on Microsoft Entra Connect Sync is near. With this change you will be able to use a TPM backed certificate in Entra Connect Sync for authentication.
This is a welcome change to prevent the compromise of this high privileged account.
#Entra #Certificate
Not really
28.04.2025 20:19 β π 0 π 0 π¬ 0 π 0I made an Azure version
microsoftedge.microsoft.com/addons/detai...
Here's (finally!) what I've found about this π
bsky.app/profile/cnot...
Is this in the Entra portal or in forwarded logs to Log Analytics
26.04.2025 19:21 β π 0 π 0 π¬ 1 π 0π Who is Nova?
We will find out tomorrow π
Here's another Maester v1.2 teaser.
We just added Severity for test results plus the ability to filter by Severity.
Great writeup
24.04.2025 21:59 β π 1 π 0 π¬ 0 π 0Looks like Lifecycle Workflows just added the ability to revoke session tokens πͺ
Previously, we had to create our own custom extension (Logic App) to do this, so really nice to see it as a built-in task now :)
learn.microsoft.com/...
Two new ASR rules are now generally available:
β½Block rebooting machine in Safe Mode
β½Block use of copied or impersonated system tools
learn.microsoft.com/en-us/defend...
Microsoft XDR Automatic attack disruption just got better. It now takes into account the device role and criticality to preserve key network functionality while protecting the assets.
Plus IP address based containment of undiscovered devices! #XDR
techcommunity.microsoft.com/blog/microso...