Abusing AUs, Confusing the SOC: Entra ID's Administrative Unit Attack Paths | SO-CON 2025

Abusing AUs, Confusing the SOC: Entra ID's Administrative Unit Attack Paths | SO-CON 2025

Source: YouTube · SpecterOps · published May 6, 2025 · 39:05

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

Katie Nolles, a cloud security researcher at Datadog, introduces a talk focused on understanding and exploiting Microsoft Entra administrative unit attack paths for both defensive and offensive security purposes 0:05.

Key Takeaways:
• The presentation clarifies the correct pronunciation of Microsoft Entra while introducing its underlying security concepts 0:14.
• The core topic revolves around administrative units, explaining what they are and how defenders can properly utilize them 0:28.
• For red teamers and pentesters, the talk outlines how to abuse administrative units for nefarious purposes to gain a deeper understanding of the feature's implications 0:35.

This introduction sets the stage for a detailed examination of Azure security by analyzing administrative units from both a defensive and offensive perspective.

Sources:

  • 0:05 Introduction to the talk on Entra administrative unit attack paths
  • 0:14 Clarification on the pronunciation of "Entra"
  • 0:28 Definition of administrative units and their defensive applications
  • 0:35 Offensive use cases for pentesters and red teamers

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Music] Uh so good morning. This talk is abusing AU's confusing the sock uh about Entra administrative unit attack paths. I had some conversations uh with some of you prior to today about the pronunciation of Entra. I've been doing it wrong so it's Entra not Entra if anyone's curious. Uh a little bit more about myself. I'm Katie Nolles. I'm a cloud security researcher at Data Dog. I focus on Azure security. And if you're not familiar with administrative units, that is totally fine. Uh we're going to talk about what they are, how to use them from a defensive perspective, but also how to use them for your nefarious purposes if you're more of a pentester, redte teamer. Um I really like this approach because it gives you a better understanding of the features. Anyways, we're going to have to d…