Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Hidden in Plain Sight - Abusing Entra's Administrative Units

fwd:cloudsec via YouTube

Overview

Explore a comprehensive conference talk that delves into the dual nature of Entra ID's Administrative Units (AUs) in Azure security. Learn how AUs function as both a defensive tool for scoping Entra ID role assignments and a potential vector for attackers seeking quiet persistence in Azure tenants. Discover the mechanisms through which obscure parameters can conceal AU membership and how restrictions can prevent the removal of malicious accounts. Follow along as Security Researcher Katie Knowles from Datadog examines Azure permissions, Entra ID role assignment, and demonstrates scenarios where AUs can be exploited for privileged tenant persistence. Gain valuable insights into detection methods, remediation strategies, and understand the implications of these double-edged administrative features. Access practical examples through Stratus Red Team, which accompanies this presentation with emulation techniques for hands-on learning.

Syllabus

Hidden in Plain Sight: (Ab)using Entra's AUs ~ Katie Knowles

Taught by

fwd:cloudsec

Reviews

Start your review of Hidden in Plain Sight - Abusing Entra's Administrative Units

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.