Overview
Syllabus
Intro
Resources
Resource Group
Management Groups
Architecture Example
Azure Resource Manager Role Based Access Control (RBAC)
Azure Active Directory (AAD) Fundamentals
Application API Access
Applications & Service Principals Authentication
Azure Active Directory Roles
Gaining Foothold - AD Connect Abuse
Internal Reconnaissance Phase
Azure Active Directory Role Assignment Enumeration
Azure Application Registration Graph App Roles Permissions
Attack Scenarios
Azure Command Line Tools
From Azure Active Directory to the Resource Manager
User Updates Application Secret
from Resource Manager to Azure Active Directory
Azure Function App - Architecture
List Function App Host Keys
OneDrive App Registration App Roles Permission
From one on-prem Machine to Another on- prem Machine
Prerequisites
Azure Tokens
Reset Application Password
Enumerating the Intune Application Permissions
Intune App graph app role permissions
Intune Script Creation
Assign Intune Script to a Group
Best Practice - Logs Logs Logs
Least Privilege Concept
Azure Resource Manager RBAC Permissions - Least Privilege
Privileged Identity Management - PIM
Azure Active Directory Identity Protection
Conditional Access
XMGoat - Compromise the Subscription
Taught by
Hack In The Box Security Conference