Tag: Identity

Azure AD
Thomas Kurth

Lessons Learned: Azure AD Conditional Access

Azure AD Conditional Access is one of the most named features which customer implement to protect their environments. But as with many cloud features at first glance it looks really simple to implement but then the complexity comes visible during rollout. Many customers activating it without thinking what the impact

Read More »

Assign AzureAD/O365 Roles based on groups

In nearly every engagement I get the question why it’s not possible to assign Azure AD roles based on Azure AD or synced AD groups. Also, in my opinion this would be a nice feature to have in a productive environment. I started building a solution based on Azure Automation,

Read More »

Implementing Azure AD Privilege Management for Azure IaaS

Two years ago, we implemented AzureAD PIM in our baseVISION infrastructure to rise the security level. But after some time, we recognized, that it has too many drawbacks because the activation of the requested role took sometimes longer than a few hours. Especially in Exchange, Skype or Intune this was

Read More »

Exploiting Active Directory Administrator Insecurities

After a weekend, full of computer enthusiasts and knowledge transfer at the Defcon 26 in Las Vegas, I am working again and wanted to share a few things I learnt there. There were a few things shown about administering active directory. In this post, I want to tell you about

Read More »