Looking for a method of preventing unauthorized access in #Azure? @rootsecdev provides an in-depth look at common Conditional Access configurations in Azure, along with potential bypasses. Read it now on our blog.
https://t.co/aqJqs1ugGn
What would it look like for an attacker to use a malicious #OAuth web app to attack Azure AD users? “Creating a Malicious Azure AD OAuth2 Application” breaks down how deploying a malicious web app isn’t overly complex and can be used in an attack #blog
https://t.co/Z5pLoL6HdP
Using a Local Account, and have Windows Hello PIN code configured? ('cause Microsoft says it's more secure 🤷♂️)
Cleartext password is in the SYSTEM vault
TPM or not
#mimikatz loves your passwords 🥰
Thank you @tijldeneut for questions on it (I was too much on PRT 🤔)