I have a new post out on the @netspi.bsky.social blog today. This one is on extracting sensitive information from the Azure Load Testing service. www.netspi.com/blog/technic...
01.07.2025 20:47 β π 3 π 2 π¬ 1 π 1@ericonidentity.com.bsky.social
Entra nerd currently @ #Semperis. Parent. Partner. MS Security MVP. Views are those of my cat.
I have a new post out on the @netspi.bsky.social blog today. This one is on extracting sensitive information from the Azure Load Testing service. www.netspi.com/blog/technic...
01.07.2025 20:47 β π 3 π 2 π¬ 1 π 1Quote of the day:
βMSFT has architected themselves into this cornerβ
#fwdcloudsec25
@ericonidentity.com
A photo taken from a train, near Heidelberg Germany, of a crop field with some brown green grass and a hazy blue sky with a tint of orange from the sunrise. There is a reflection on the window of myself somewhat from inside the train car.
Going right from @wearetroopers.bsky.social in Heidelberg to @fwdcloudsec.org in Denver βοΈ - from one excellent conference to another!
Iβm looking forward to speaking Monday @ 2:00pm in track 1 on the dangers of #nOAuth, with some new and tweaked slides and talking points!
#Entra #EntraID
nOAuth revisited by @ericonidentity.com at @wearetroopers.bsky.social
25.06.2025 14:06 β π 3 π 2 π¬ 0 π 0At @wearetroopers.bsky.social I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable SaaS applications. The attack is still alive and well.
You can read all about it here:
#Entra #M365 #infosec
www.semperis.com/blog/noauth-...
A photo taken from an airplane of the. There are small white fluffy clouds scattered below and a slightly hazy blue sky with white wisps above them.
On the way to #TROOPERS25. The short flight is down⦠just waiting for the long one to Frankfurt.
Looking forward to talking about #nOAuth with #Entraβ¦ sadly itβs still a thing π
#EntraID #infosec @wearetroopers.bsky.social
Did you know you can send LAPS passwords to Entra on Server OS? Neither did @adamgrosstx.bsky.social or I until yesterday! Just need to hybrid join the server(s) and set the GPO to backup to "AAD"! Neat!
30.04.2025 00:33 β π 15 π 4 π¬ 2 π 1In 2019, before the AZ-104 days, I failed AZ-101 the first time aroundβ¦
17.04.2025 16:23 β π 1 π 0 π¬ 1 π 0A picture taken from inside an airplane out the airplane window. The plane is on the ground, and the picture shows the jet bridge for the next gate with some workers outside. Itβs still dark outside.
Obligatory photo from airplane en route to the #mvpsummit
22.03.2025 09:29 β π 6 π 0 π¬ 0 π 0Now do Yggdrasil π
20.03.2025 15:39 β π 2 π 0 π¬ 0 π 0The last two months have been a chaotic whirlwind of emotions and activity. I needed to talk about it, so I did: jakehildreth.github.io/blog/2025/03...
09.03.2025 00:10 β π 7 π 1 π¬ 1 π 0Yesterday morning, I woke up to an email from Microsoft with the subject "Congratulations on your Microsoft MVP award". I immediately thought it was a phish, but I dug a bit further.
It's real! π€― I was selected as an MVP in "PowerShell" and "Identity & Access"!
π’ To all attendees, sponsors, and speakers of MC2MC Connect!
πΈ We have uploaded all the event photos to the Gallery page on the MC2MC Connect website, so you can look back and relive the day!
π connect.mc2mc.be/gallery/
#MC2MC #ConnectMC2MC #MC2MCConnect
If you work in, around, near, adjacent, or so on, to #identity, including #infosec and #Entra, you should fill out the #IDPro skills survey. It takes five minutes and really helps in understanding the industry landscape.
www.surveymonkey.com/r/L9QB6T2
I received an interesting #M365 subscription email the other week, that turned out to be a scam.
I figured I'd pick it apart, and found it curious enough to share the details.
#entra #infosec #m365security #azure
ericonidentity.com/2025/02/20/a...
Not yetβ¦ π¬. Congrats to you though! Iβm hoping Iβll be there regardless of speaking to catch your talk!
04.02.2025 23:48 β π 1 π 0 π¬ 0 π 0Weβre pleased to announce the next speaker for MC2MC Connect: @ericonidentity.com π
In this session, Eric will dive deep into the most common questions about app registrations, enterprise apps, and service principals. ππ‘οΈ
π tinyurl.com/5dxvnsn4
#MC2MC #ConnectMC2MC
Zuckerberg "loved" an AI slop image on a spam page that also posts AI images of children with amputations, elderly people, fake images of graves, links offsite to ad-loaded pages, etc. Exciting stuff for me
www.404media.co/zuckerberg-l...
If you consume multi-tenant apps in #EntraID, and theyβve been granted consent to do things in your tenant, you can spy on the auth choices your vendor makes - secrets or certs - in the logs available in your #Entra tenant.
#infosec #m365 #azure
ericonidentity.com/2025/01/13/s...
Oh Iβve submitted a few things at various placesβ¦ hoping to be at Identiverse one way or another this year
10.01.2025 21:52 β π 2 π 0 π¬ 1 π 0With all the speaking I burnt and crashed a bit towards the end of 2024. I plan on writing about the speaking experienceβ¦ but first hoping to get back into writing more as I research stuff. Hope to have both a personal blog and Semperis blog article out this week π€.
09.01.2025 00:33 β π 8 π 0 π¬ 2 π 0A screenshot of a portion of an email from MSRC for the 2024 W4 leaderboard with two valid cases totaling 75 points.
Looking forward to when I can talk about the more interesting case π #MSRC #Entra
04.01.2025 20:57 β π 4 π 0 π¬ 1 π 0Yup π«‘
19.12.2024 14:24 β π 1 π 0 π¬ 1 π 0From what I gathered listening to it the other week at a partner event my takeaway was scenario #1 as well. I was going to ask the question in line with what youβre wondering; or at least I was wondering about fidelity/granularity. But I already was scolded for asking non-sales questions π
13.12.2024 22:34 β π 2 π 0 π¬ 1 π 0Great advice; received a variant of this last week that had an old password I used to use in it π
13.12.2024 22:30 β π 0 π 0 π¬ 0 π 0Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID, which is a hardcoded and undocumented exclusion in CA for device compliance. It has user_impersonation rights on the AAD Graph π
12.12.2024 16:00 β π 46 π 20 π¬ 3 π 1Pretty sure the two green checkmarks means itβs doubly verified valid
11.12.2024 21:57 β π 2 π 0 π¬ 0 π 0NTLM v1 is removed from the latest version of Windows
Oh by the way
06.12.2024 01:08 β π 102 π 35 π¬ 9 π 6The Moynihan Train Hall Starbucks is an absolute machine of efficiency.
05.12.2024 13:43 β π 0 π 0 π¬ 0 π 0