Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Bringing Your Own Identity Provider to Entra for Persistence and MFA Bypasses

x33fcon via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore how to create custom Identity Provider implementations in Entra ID (formerly Azure AD) to bypass Multi-Factor Authentication and establish persistence in this 46-minute conference talk. Learn about the OpenID Connect protocol vulnerabilities in Entra ID features like Federated Credentials, External Authentication Methods, and Custom Controls that allow external providers to perform authentication or control MFA. Discover techniques for adding authentication backdoors to existing MFA providers and bypassing security controls without requiring custom platforms. Examine various vulnerabilities encountered during security research that enable attackers to maintain persistence and circumvent authentication mechanisms. Get hands-on insights into using the updated roadoidc tool from ROADtools to perform these attacks, while also understanding the defensive indicators security professionals should monitor to detect such activities in their environments.

Syllabus

6. Dirk-jan Mollema: Bringing Your Own Identity Provider to Entra for Persistence and MFA Bypasses

Taught by

x33fcon

Reviews

Start your review of Bringing Your Own Identity Provider to Entra for Persistence and MFA Bypasses

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.