Bypassing Entra ID Conditional Access - A Deep Dive Into Device Authentication Mechanisms
Offered By: Black Hat via YouTube
Course Description
Overview
Dive deep into the internal workings of device authentication in Entra ID Conditional Access through this conference talk. Explore how attackers can potentially bypass device authentication without administrator privileges by interacting with device certificates and session keys protected by TPM. Learn about the discovered attack implemented through reverse-engineering Microsoft authentication library, which currently has no fix. Walk through the details of the device authentication flow, attack mechanisms for bypassing Conditional Access, and gain insights into defending against and detecting such attacks. Understand the implications for securing Microsoft cloud infrastructure and the challenges in applying appropriate access controls.
Syllabus
Bypassing Entra ID Conditional Access Like APT: A Deep Dive Into Device Authentication Mechanisms
Taught by
Black Hat
Related Courses
Microsoft Cybersecurity Stack: Advanced Identity and Endpoint ProtectionLinkedIn Learning Administering Active Directory and Entra ID
Pluralsight Designing and Implementing Active Directory and Entra ID
Pluralsight Microsoft Security, Compliance, and Identity Fundamentals: Identity and Access Management Solutions
Pluralsight Credential Management and Access Control with Active Directory and Entra ID
Pluralsight