Offensive Entra ID (Azure AD) and hybrid AD security
February 1st, 2nd & 3rd
Intermediate
Speakers:
Description
Many companies rely on Microsoft Entra ID (formerly Azure AD) as an identity platform for their cloud services, often using their existing on-prem Active Directory as a source for a hybrid setup. As a red teamer, pentester, or security architect, you are probably familiar with Active Directory security concepts. Entra ID is vastly different and is built around different concepts and protocols.
This training explains how organizations use Entra ID to manage modern cloud-based or hybrid environments and what attacks are possible against Entra ID tenants and users. It is the result of many years of research into the protocols and internals of Entra ID. It will give you the knowledge to analyze, attack, and secure Entra ID and hybrid setups from modern threats. The training is technical and deep-dives into core protocols such as OAuth2 and application concepts. It includes many labs and hands-on exercises, set up as challenges to gain access to accounts and elevate privileges. More info on the topics covered is available on our website. The training and all course materials are available in English only.
Course Level
Intermediate
Course Requirements
To participate in the training exercises, participants will need a laptop with a virtualization platform (such as VMWare Workstation / Player) with a virtual machine that can be used for the labs in the training. All exercises can be done from both Windows or Linux based virtual machines, if you are unsure which one to choose, a Windows machine is recommended. If you are using a corporate laptop, please make sure that you have unrestricted internet access to connect to the lab VPN and authenticate to other Entra ID tenants.
Key takeaways
It will give you the knowledge to analyze, attack, and secure Entra ID and hybrid setups from modern attacks.



















