UnOAuthorized: A Technique to Privilege Escalation to Global Administrator
Google Data Analytics, IBM AI & Meta Marketing — All in One Subscription
NY State-Licensed Certificates in Design, Coding & AI — Online
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
This Black Hat conference talk reveals a novel privilege escalation technique that allows attackers to gain Global Administrator access in Microsoft 365 and Azure environments - the cloud equivalent of Domain Administrator privileges. Explore the research background and foundational components that enable this security vulnerability, following a detailed step-by-step walkthrough of how attackers can bypass well-defined role-based access controls and application consent models to achieve the highest level of cloud privileges. Senior Cloud Security Architect Eric Woodruff from Semperis demonstrates this critical security finding that should concern any organization using Microsoft's cloud services, as it represents a significant threat vector that could lead to complete environment compromise.
Syllabus
UnOAuthorized: A Technique to Privilege Escalation to Global Administrator
Taught by
Black Hat