Speaking at #TROOPERS26 next week and I can't wait. Joining @martinsohn.dk to talk about attack paths to #PAW and real-world risks of tiered admin models with #IntuneRBAC. Plus something we've been working on for months... See you in Heidelberg! www.troopers.de #EntraOps #Bloodhound
Thomas Naunheim
@naunheim.cloud
#Microsoft MVP | #CloudSecurity Architect ☁️ | #Entra #AzureAD 🔑 + #AzureSecurity 🛡️ | #CommunityRocks | #Schaengel
[New blog post] Analyzing #MicrosoftEntra 🤖 Workload Identity Activity Through 🪙 Token-Based Hunting: I’ve published a #KQL function to hunt activities by tokens from non-human identities and share some experimental queries and insights in this article. www.cloud-architekt.net/token-huntin...
Analyzing Workload Identity Activity Through Token-Based Hunting
This post introduces the MicrosoftCloudWorkloadActivity KQL function and shows how to hunt token-based activity of workload identities across Microsoft cloud workloads. It covers key parameters, filte...
cloud-architekt.net
#ConsentFix is a great way for attackers to work around some protective layers but not all. @naunheim.cloud , @cbrhh.bsky.social and I wrote a blog post on detection and mitigations. Hope you find it useful and can adapt it to your environment. www.glueckkanja.com/de/posts/202...
Had the great privilege and a lot of fun joining 🎙️#EntraChat together with my friend and MVP fellow @samilamppu.bsky.social! 🙏 Big thanks to @merill.net for having us - it was a pleasure to be part of the podcast. I hope everyone listening enjoyed it as much as we did recording it!
Thomas Naunheim and Sami Lamppu quietly built one of the most useful open projects for Entra ID defenders. The Entra ID Attack & Defense Playbook It’s free, community-driven, and packed with real detection logic and KQL queries. 🧵👇
The availability of GraphApiAuditEvents in #MicrosoftDefender brings significant value to every environment, enhancing capabilities for detecting and hunting #MicrosoftGraph API calls. In my recent research, I’ve created a few resources that I’m happy to share with the community.
🚀🔎 Track Sensitive Graph API Calls with my new #KQL Function for #MicrosoftDefenderXDR Microsoft has released the new advanced hunting table "GraphAPIAuditEvents" which offers great opportunities to investigate activities based on #MicrosoftGraph API calls.
My session, “Defending Tier 0: Taking Control of Your Cloud’s Control Plane,” from last year’s #HIPConf is now available on YouTube. The session focused on securing privileged access and implementing a tiered administration model in #MicrosoftEntra. youtu.be/pVPEieHtOVM
Defending Tier 0: Taking Control of Your Cloud's Control Plane
YouTube video by Semperis
youtu.be
I've published a #KQL function ("WorkloadIdentityInfoXDR") for #MicrosoftDefender to enhance details of #MicrosoftEntra #WorkloadID from various sources, incl. the new table "OAuthAppInfo" but also IdentityInfo table and #ExposureManagement. (1/2) 🔗 github.com/Cloud-Archit...
Cloud #IdentitySummit 2025 is back! Save the date and join this community event with #IdentitySecurity, #MicrosoftEntra, and #CloudIdentity deep dive sessions in Dortmund, Germany. Call for Papers is open now: sessionize.com/cloud-identi... Stay tuned for more details: www.identitysummit.cloud
IdentityInfo table in #MicrosoftDefender has been expanded to include eligible roles from #MicrosoftEntra. I’ve developed a #KQL function to get a summarized overview of all directory role assignments, enriched with details from my #EntraOps classification: github.com/Cloud-Archit...
I had the great pleasure of speaking about #MicrosoftEntra Token Hunting 🍪🔎 at #YellowHat 🚧👷♂️. You can find the slides from my session here: 📄 github.com/Cloud-Archit... All #KQL sample queries are available in my repo: 👨💻 github.com/Cloud-Archit...
I have the great pleasure of joining a shared session with @samilamppu.bsky.social at the M365 Security & Compliance User Group tonight. Last preparations are now in full swing... You can find more details about the meetup and register for this free online event here: www.meetup.com/m365sandcug/...
Enhancements in #MicrosoftEntra (diagnostic) logs: Several interesting sign-in properties (including Session ID, status for Token Protection, or GSA traffic) have been added to the sign-in logs and available in #MicrosoftSentinel. (1/3)
I'm building a new home for IntuneBrew and would like to share my progress so far. IntuneBrew.com will serve as the project's landing page, featuring a Quick Start Guide and an overview of key features.
Do you like to know if ownership of privileged objects in #MicrosoftEntra has been delegated to lower privileged users? Graph semantics in KQL and XSPM allow building powerful queries and analyzing data as graphs. I've started to include data from #EntraOps to analyze delegated ownership. (1/3)
Final touches and rehearsal for my #TECTalk on #TokenSecurity in #MicrosoftEntra tonight. I'll be discussing attack scenarios on various token types and how TPM, Token Protection, CAE & Global Secure Access can help prevent token theft. Register for the free webinar: www.quest.com/event/the-ex...
How can you detect and mitigate #MicrosoftEntra Compliant Device Bypass in the #MicrosoftIntune Company Portal? What are the potential attack paths? @fabian.bader.cloud, @cbrhh.bsky.social and I had additional research and summarized our results in this blog post: www.glueckkanja.com/blog/securit...
Compliant Device Bypass in Microsoft Intune – Detection, Response & Mitigation
In this blog post, glueckkanja's MVP Fabian Bader, Chris Brumm and Thomas Naunheim gather details about the Compliant Device Bypass in Microsoft Intune Company Portal. After additional research, they ...
glueckkanja.com
#MicrosoftEntra Attack & Defense Playbook Update: @samilamppu.bsky.social and I have updated some content: 🔃 #EntraConnect: New capabilities by MDI sensor & XSPM 🎯 #AiTM: Attack scenarios on MDA sessions 🛡️ #MITRE: Updated TTP coverage & map Check out the latest version: github.com/Cloud-Archit...
GitHub - Cloud-Architekt/AzureAD-Attack-Defense: This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can b...
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected. - Cloud-Architekt/Azu...
github.com
We’re excited to announce the next speakers for MC2MC Connect: @naunheim.cloud and @ugurkoc.de 🚀 In their session, they’ll show how to configure Platform SSO in Intune and highlight its benefits for user experience and security. 🎟️ tinyurl.com/5dxvnsn4 #MC2MC #ConnectMC2MC
Am 11.04.2025 findet die #ExpertsLiveDE in Leipzig statt, mit vielen spannenden Vorträgen zu Cloud, Workplace, AI und Security. Ich freue mich sehr, dieses Jahr dabei sein zu dürfen und über #TokenTheft in #MicrosoftEntra sprechen zu dürfen. Weitere Infos sowie Tickets: www.expertslive.de
Do you like to learn more about tokens and ways to protect them in #MicrosoftEntra? Join my #TECTalk on January 23rd to explore the various kind of token artifacts, post authentication attacks and mitigations to prevent #TokenTheft. Register for free at www.quest.com/event/the-ex...
So who wants a verified 'Microsoft' and 'Microsoft MVP' label on their profile and all the posts? I just finished setting up @bluesky.ms as a labelling service. Go subscribe to the label to start seeing labels on verified MVPs and Microsofties. 🧵👇
New Release: #EntraOps 0.3.3! 🚀 This update includes bug fixes and enhancements to #MicrosoftSentinel workbooks and nested #MicrosoftEntra PIM for Groups. Get the latest version from the GitHub repository: github.com/Cloud-Archit...
Celebrating 4 years of the "#MicrosoftEntra Attack & Defense Playbook" 🔐 ☁️ community project! Last week, @samilamppu.bsky.social and I took the opportunity to record a video about the journey of this project, from research to writing process. #MVPBuzz #TechCommunity www.youtube.com/watch?v=fBD1...
Microsoft Entra ID Attack & Defense Playbook with Sami Lamppu
YouTube video by Thomas Naunheim
youtube.com
Next week, I have the great pleasure to speak together with @gregorreimling.bsky.social at APE XXL in Apenheul, NL. We'll be sharing best practices in various design areas of #Azure #EnterpriseScale. Get your tickets for a day full of #Azure breakout sessions and workshops: xxl.azure-ape.nl
Just wrapped up day 3 of #MSIgnite with @adrianritter.bsky.social, @okieselb.bsky.social and @ugurkoc.de. Our latest video covers all the recent announcements and sessions about SSE, Data Governance, Intune's AI management on macOS, and #Copilot. Tune in! youtu.be/wjri-1EvPSw?...
Microsoft Ignite 2024 - Day 3 Recap
YouTube video by Thomas Naunheim
youtu.be
Day two of #MSIgnite was packed with sessions about #MicrosoftEntra and #Intune: @ugurkoc.de, Oliver Kieselbach and I will talk about device query actions, some updates and showcases across Entra suite, and much more. Check out our latest video from Chicago. youtu.be/p10M1dx9mco?...
Microsoft Ignite 2024 - Day 2 Recap
YouTube video by Thomas Naunheim
youtu.be
Day two of #MSIgnite: Delving into the latest announcements and features for #MicrosoftEntra has been a focus today for me, and I’ve enjoyed the following sessions.