I Trusted You - A Demonstrated Abuse of Cloud Kerberos Trust
fwd:cloudsec via YouTube
AI Adoption - Drive Business Value and Organizational Impact
Our career paths help you become job ready faster
Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore a detailed conference talk that delves into the security implications of Cloud Kerberos Trust in Microsoft's Windows Hello For Business setup. Learn about the vulnerabilities created when authenticating between Azure AD and traditional Active Directory, particularly focusing on how the delegation of authentication material to Azure AD can be exploited. Discover how attackers can breach the Cloud/On-Premises security boundary by authenticating as non-synced on-premises users, bypassing the need for administrator synchronization to Azure AD. Understand the fundamental challenges of synchronizing data between two authoritative sources and gain practical insights into identifying potential misconfigurations in your environment. Master mitigation strategies to protect against these security vulnerabilities and maintain a robust authentication framework across cloud and on-premises infrastructure.
Syllabus
I Trusted You A Demonstrated Abuse of Cloud Kerberos Trust - Daniel Heinsen, Elad Shamir
Taught by
fwd:cloudsec