IGA/IAM & IT Infrastructure Architect - Thoughts expressed here are my own and not to be connected with my professional role though they sometimes coincide
🗺️ 𝗥𝗕𝗔𝗖𝗠𝗮𝗽 - 𝗜𝗻𝘁𝗲𝗿𝗮𝗰𝘁𝗶𝘃𝗲 𝗺𝗮𝗽 𝗼𝗳 𝗠𝟯𝟲𝟱 𝗥𝗕𝗔𝗖 𝗿𝗼𝗹𝗲𝘀
Just came across this cool tool built by 𝗝𝗮𝗰𝗼𝗯 𝗦𝗵𝗲𝗿𝗶𝗱𝗮𝗻 (𝗦𝗲𝗻𝗶𝗼𝗿 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗣𝘂𝗿𝘃𝗶𝗲𝘄 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿) and sharing it with fellow defenders.
𝗥𝗕𝗔𝗖𝗠𝗮𝗽 𝗰𝗼𝘃𝗲𝗿𝘀 𝟵 𝘀𝗲𝗿𝘃𝗶𝗰𝗲𝘀 𝗮𝗻𝗱 𝟯𝟮𝟳 𝗿𝗼𝗹𝗲𝘀: Entra, Purview, Intune, Exchange, SharePoint, Defender XDR, Fabric, Power Platform, and Security Copilot.
For each role you get:
• Permissions and scope
• Use cases and when to assign it
• Prerequisites, best practices, and security considerations
• Service-specific gotchas and related roles
Tool's link:🫡
https://t.co/U7u3emEmsn
#Cybersecurity #RBACMap #RBAC
Microsoft just moved Purview under the same exec who leads Intune.
What does it mean for Intune admins?
Time to start learning Purview?
@IAMERICAbooted says yes 😀
‼️🚨 Microsoft calls this "intended behaviour," so here we go.
How to dump the credentials of every user stored in Microsoft Edge:
1. Open Edge. Don't browse anywhere, just open it.
2. Flip to Task Manager, find Edge, expand the task.
3. Highlight the "browser" sub-task, right-click, and choose "Create Memory Dump."
4. Open the dump file and look for credentials.
The logged-in Windows user can dump every stored Edge credential with no additional rights. Which means any malware that user executes has those credentials for the asking.
Thanks to Rob VandenBrink at SANS: https://t.co/ebtVZxne4L
🛡️ Microsoft Active Directory Domain Services Flaw Let Attackers Escalate Privileges
Source: https://t.co/jgNrsXEzjn
A high-severity flaw in Active Directory Domain Services (AD DS). The attack operates entirely over the network, requires minimal privileges, has low attack complexity, and requires no user interaction. It heavily impacts the confidentiality, integrity, and availability of the system.
Tracked as CVE-2026-25177, it allows authorized network attackers to elevate their privileges to full SYSTEM control.
The attack operates entirely over the network, requires minimal privileges, has low attack complexity, and requires no user interaction. It heavily impacts the confidentiality, integrity, and availability of the system.
#cybersecuritynews
I am the Chief Information Officer of a global enterprise.
Last quarter, I eliminated MFA.
Multi-factor authentication. The thing where you need two things to log in instead of one.
It created friction.
Employees complained. "Why do I need a code from my phone?" "This slows me down." "I forgot my authenticator app."
I listened.
That's leadership.
I told the board: "We're removing barriers to productivity. Empowering our workforce. Choosing agility over friction."
They promoted me on the spot.
The CISO wept, no one likes him anyway.
Our CISO is a Debby Downer.
Our file-sharing portal now requires one thing: a password.
Passwords are secure. People choose strong ones.
They definitely don't reuse them across every website they've ever visited.
That's just common sense.
Last week, a criminal named Zestix stole our data.
Also 49 other companies.
Fifty organizations. One guy. One method: log in with stolen passwords.
No exploits. No zero-days. No sophisticated nation-state attack.
Just... passwords.
The passwords came from infostealer malware. Employees downloaded infected files. The malware grabbed their saved credentials.
Some of those credentials had been sitting in criminal databases for years.
We didn't rotate them.
Password rotation creates friction.
Zestix targeted our ShareFile portal. The one with all our sensitive documents.
Engineering data for three major utilities. He's selling that for $585,000.
Military robotics intellectual property from an aerospace company.
2.3 terabytes of Brazilian Military Police health records.
Active legal strategies from a law firm representing Mercedes-Benz.
Technical safety data from Spain's largest airline.
SCADA drawings and GPS coordinates of control rooms for a rail company.
Fifty organizations.
No MFA.
Hudson Rock, the security firm that tracked this, wrote: "The attacker walks right in through the front door. No exploits, no cookies – just a password."
I prefer to frame it differently.
The attacker was welcomed in through an optimized authentication experience.
We trusted our employees. We trusted our partners. We trusted that everyone uses unique, complex passwords that they never share or reuse.
That's culture.
Some people will say we should have enabled MFA.
Those people don't understand velocity.
Some people will say we should rotate credentials.
Those people haven't seen our Q4 productivity metrics.
Some people will say Zestix is a criminal.
I prefer "external penetration testing consultant we didn't hire."
The data is now on the dark web.
Our security team is investigating.
Our legal team is drafting statements.
Our HR team is preparing the employee communication.
Subject line: "Protecting What Matters: Our Commitment to Your Data."
We're also launching a mandatory cybersecurity training.
Module 1: "Why Passwords Are Your First Line of Defense."
Module 2: "Recognizing Phishing Emails."
Module 3: "The Importance of Multi-Factor Authentication."
That last module is new.
We're requiring it for all employees.
The training, I mean.
Not the MFA.
MFA still creates friction.
Attention IT Pros! The Microsoft UEFI CA, which SecureBoot relies on, will expire on Monday October 19, 2026, after 15 years of validity. Mark this date in your calendar. Devices require a Firmware/DB update; otherwise, stop booting. 🔒#WindowsSecurity
https://t.co/Tl8nF5TdXe
Microsoft says meeting time has TRIPLED since 2020: typical workers are spending 57% of their time communicating [meetings, calls] with others: 'Today, knowledge work is, quantitatively speaking, less about creating new things than it is about talking about those things.’
Table Top Scenario:
An employee buys a new personal laptop with Copilot+ Recall.
User logs into a company approved portal secured with MFA and a VDI session to work on a highly confidential project that involves PII. Recall is on and taking screenshots of the employees productivity.
A few weeks later the employees personal device is stolen. The laptop hard disk was never encrypted. Feel free to discuss.
Fear and loathing in IT: the April 2024 security update for Windows Server will cause a significant increase in NTLM authentication traffic on Active Directory domain controllers.
See https://t.co/cJxcmgVvmQ for the known details. https://t.co/raCFIlRTWF