Coding Stephan

#Azure AD

Speaking at ESPC23 - Protect your API with Entra ID

Speaking at ESPC23 - Protect your API with Entra ID

Hiding in plain Graph, an issue with Azure AD Audit log

Hiding in plain Graph, an issue with Azure AD Audit log

Proof of concept: Multi tenant managed identity

Proof of concept: Multi tenant managed identity

Hacking Primary refresh tokens, oops created a virus

Hacking Primary refresh tokens, oops created a virus

Using a managed identity as a client credential

Using a managed identity as a client credential

Federated credentials, wait what?

Federated credentials, wait what?

Protect against certificate extraction - Client credentials

Protect against certificate extraction - Client credentials

Extract all Azure AD admin accounts

Extract all Azure AD admin accounts

Extract all users with powershell and what you should do about it

Extract all users with powershell and what you should do about it

Access Azure AD protected API with managed Identity

Access Azure AD protected API with managed Identity