Purple Teaming Azure IAM for Threat Detection

Purple Teaming Azure IAM for Threat Detection

Source: YouTube · SANS Cloud Security · published Oct 30, 2025 · 25:05

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

This presentation introduces the concept of purple teaming within Azure Active Directory (Azure AD) to enhance threat detection capabilities. 0:07

Key Takeaways:
• The speaker, Lydia Grassley, is a threat detection engineer at Edward Jones and a SANS instructor, bringing a unique perspective from her background in English teaching and international relations. 0:02
• Purple teaming in Azure AD involves collaborative red and blue team activities to validate detection rules and improve security posture. 0:10
• The session includes humorous elements, such as "snakes on a plane" imagery, to engage the audience while discussing technical topics. 0:15
• Understanding Azure AD threats is critical, as attackers frequently target cloud identities to gain initial access. 0:13

Purple teaming serves as a vital bridge between offensive testing and defensive monitoring, ensuring that security controls are effective against real-world attacks.

Sources:

  • 0:07 Introduction to purple teaming in Azure AD
  • 0:02 Speaker background and credentials
  • 0:15 Mention of "snakes on a plane" theme
  • 0:13 Importance of Azure AD security

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

My name is Lydia Grassley. I'm a threat detection engineer at Edward Jones. And today we're going to be talking about purple teaming in Azure, specifically Azure AM. Um, and also we're going to have a bunch of silly pictures about snakes on a plane because snakes on a plane. All right. So, um, about me, I'm a threat detection engineer at Ed Edward Jones. I'm also now a TA for SANS cloud threat detection in 541. I'm actually teaing this week. So, if you're in 541, you'll be able to hang out with me and Ryan for a day on Saturday and then I'm going back to DC. Um, I'm a former English teacher. I am a career changer. I went to China for a year. I taught English. Got really into international relations. Did a paper on cyber security policy. Um, specifically Mandians AP1. I thought this was the…