Evading Entra ID Protection: Red Team Tradecraft Against Modern Identity Defenses | Webinar

Evading Entra ID Protection: Red Team Tradecraft Against Modern Identity Defenses | Webinar

Source: YouTube · Altered Security · published Jun 13, 2026 · 2:43:25

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

This webinar demonstrates that Microsoft Entra ID Protection is limited to detecting sign-in events, allowing attackers to evade detection and conditional access policies by obtaining and using non-revocable access tokens via device code phishing or Azure IMDS 0:37.

Key Takeaways:
• Entra ID Protection monitors sign-in risks like impossible travel and anonymous IPs but cannot detect usage of access tokens, as resource servers only validate the bearer token 0:37 15:20
• Workload identities (service principals, managed identities) are significantly harder to detect than user identities and are preferred targets for evasion 12:45
• Access tokens obtained via device code phishing or Azure Instance Metadata Service (IMDS) bypass conditional access and cannot be revoked by the identity provider 14:50 18:30
• Tokens issued through Azure IMDS have a lifetime exceeding 24 hours, compared to the standard one-hour expiration, extending the window of access 18:30
• Participants must use Discord for discussion as microphone privileges are restricted to the host only 0:59 1:02
• The Discord server link is available at alteredsecurity.com for participants to access labs and discussions 1:13 2:10

The fundamental evasion strategy is avoiding sign-in events entirely by obtaining access tokens through alternative means, exploiting Entra ID Protection's limitation to the authentication layer.

**Sources

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 2 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hi everyone. Okay. So, welcome to the IIDin Entra ID Protection webinar. We still have uh 30 more minutes. So, let's get started with introductions. So those of you who have been attending these webinars in uh the month of Azure red teaming would know that uh we are not allowing you the participants to use your mic. All right, that privilege rests with the uh host. So uh while we start this formally in 13 minutes before that let's get to know each other. If someone would like to introduce themselves on the discord server please go ahead. So just your name if you would like to share it. Not even that just your background and your city or country if you want to share that. Um, is it possible to get the discord link? I didn't get that in the emails. >> Okay, but I'll put that in the chat. And…