
Bring Your Own Policy: Weaponizing ADMX for Cloud-to-On-Prem Lateral Movement | Hacker Summer 2026
Source: YouTube · Altered Security · published Aug 3, 2026 · 1:37:20
This webinar details a "Bring Your Own Policy" attack that weaponizes Microsoft Intune Administrative Templates via the Office 365 Client Admin App to achieve remote code execution and lateral movement from cloud to on-premises environments 0:40.
Key Takeaways:
• Intune’s MDM capabilities allow high-privilege script execution, making it a primary target for cloud-to-on-prem lateral movement 10:00.
• Microsoft patched direct PowerShell script execution via the Intune Company Portal in August 2025 by removing necessary permission scopes 40:50.
• Researchers discovered a novel technique using the "Office 365 Client Admin App" ID to push weaponized ADM policies, bypassing script restrictions 41:30.
• The attack utilizes a specific registry key (HKLM\Software\Classes\CLSID\{...}\shell\opennewwindow\command) not blocked by Intune, allowing code execution when File Explorer is opened 57:20.
• The demonstration showed downloading a reverse shell via curl and executing it using installutil.exe to evade Windows Defender detection 59:30.
• Defense strategies include enforcing U2F/FIDO2 keys for admin accounts, enabling multi-admin approval for sensitive actions, and monitoring for bulk policy changes 21:50.
This research highlights the evolving nature of hybrid cloud attacks, where threat actors continuously adapt to Microsoft's security patches by finding new legitimate features to abuse for persistent access.
Sources:
- 0:40 Introduction to the "Bring Your Own Policy" attack vector and webinar context.
- [10:00](https://www.youtu
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hello, everyone. Yes. Am I audible and also visible since it's. Yes yes yes yes. So let me share my screen and formally start our webinar. So. Good morning. Good afternoon and good evening to everyone joining us
from different parts of the world. Welcome to the last webinar
of Altered Securities Hacker summit 2026. Our topic for today is bring your own policy weaponizing ADM for cloud to on prem lateral movement. So before we go ahead, it's very important that we introduce
ourselves for those who have joined for the first time or who don't know
much about Vishal and I. Let me go ahead and do so. So my name is. I'm a security researcher here
at Altered Security. I have about seven
and a half years of experience in this domain,
and in these seven and a half years, I have about both the offe…