Reduce your Intune Admins and use intune rbac and restricted admin units. Segregate device management into groups to decrease the blast radius. Treat Intune Admins like Global Admins. Require PIM with approvals. I've been saying this since before it was popular.
As unpopular as this may sound right now, Microsoft is not to blame. They wrote about how to do all this in their documentation, but nobody does it.
You have to keep in mind that it could have been a Global Admin too. In that case, the situation is even more dire.
The vast majority of orgs are still hybrid. If the compromise was of the on-prem AD, not much you can do because you can pivot to an Intune Admin's device and use the APIs. This is why your EDR should be throwing high alerts when admin machines stop checking in and you should validate visibility on those machines. Managing admin machines is really really hard. Admins write code, run scripts, and look like they are compromised all the time when they're not.
Stop everything. Advent of Cyber 2025 has officially entered the chat…and it's LIVE! 🎄 🚀
24 Days. 24 Challenges, filled with a full festive storyline, beginner friendly and completely free!
And did we mention the $150,000 in prizes waiting for you?! 👀 🔥
If you’ve ever wanted to learn cyber security… THIS is your moment.
If you’ve done AoC before… you already know the magic.
If you’re hesitating… don’t.
What are you still doing here?
👉 Join Advent of Cyber 2025 https://t.co/HrCNLSLY5e
The more I learn about the semiconductor supply chain, the more implausible it all seems. There’s a small island vulnerable to invasion where all the chips are made? And the machines to make them all come from one firm in the Netherlands? Using lenses made by one firm in Germany?
I still cannot believe that I can:
- look at a world map and tap anywhere to zoom in at street level
- instantly access any song, book, movie, tv show, or podcast ever made
- have any conceivable question and get an immediate answer or video explanation
- take a photo or video wherever I am and add it to my massive, searchable, always accessible personal archive
- video call anyone in my life, at anytime, no matter where they are
- watch live sports on a little wireless glass rectangle
- type out these thoughts and have them read by thousands of people, all over the world, a few seconds later
10% of international web traffic is protected by a wall of lava lamps in San Francisco which converts the changes in randomness of the bubbles into computer code.
Want to play a fun prank on an Azure admin you know?
1. Create an account in your own tenant, configure SMS MFA w your target's phone.
2. Log in, which sends an SMS.
3. Sit back and watch them as they try to figure out which account is compromised!
4. Repeat login until they've gone completely mad.
Microsoft MFA SMS messages don't say what account they are for. Great design.
I wonder how much of SpaceX’s success is just not messing around. Like, if your launch is being held up by the chopsticks needing some major servicing, why NOT just rent every lift in the county and get it down immediately?