Sonny

234 posts

Sonny

Sonny

@SonBoyJim

Katılım Mayıs 2009
832 Takip Edilen36 Takipçiler
Sonny retweetledi
Merill Fernando
Merill Fernando@merill·
Why did I leave Microsoft? To work full time on 🔥 Maester. Over 40,000+ tenants today rely on Maester to monitor their tenants daily. I wanted to make sure that the tests they are running continue to be relevant and evolve as Microsoft 365 and the security landscape evolves. So today I'm announcing the launch of Maester.Cloud Maester Cloud is the portal companion to Maester that lets you track your results over time. It is multi tenant, runs in your cloud (or ours) and more → check out the site for all the features. More importantly Maester Cloud is a way for me to fund the continued development of the open source Maester core and the tests in Maester. That is our mission. In fact I worked with the core team @fabian_bader , @Thomas_Live , @MySnozzberries and @SamErde to create the Maester Manifesto (maester.cloud/manifesto). It is our promise to the community. If you value Maester and would like to support and ensure that Maester continues to grow and be healthy, I would be beyond thrilled if your organisation can sponsor this effort. I would also appreciate it very much if you can share this post with your network to spread awareness. Thanks!
Merill Fernando tweet media
English
40
157
572
56.2K
MrBeast
MrBeast@MrBeast·
First person to reply with the exact number of pennies in this room win $10,000
MrBeast tweet media
English
474.6K
7K
210.7K
51.7M
EZ
EZ@IAMERICAbooted·
Merill Fernando @merill and I sat down for another Entra Chat last month to talk about how attackers have been known to use those loose SECRETS SECRETS EVERWHERE, even to compromise Microsoft's tenant! If an attacker gets their hands on a secret or certificate+key for an app registration that has application (not delegated) permissions, your conditional access policies and named locations or zones WILL NOT MATTER. They will be able to leverage that API permission acting as an application, from anywhere. Attackers are smart. They will make it blend in with where those service principals normally act from. So, do your best to clean them up so you don't lose control of your environment. When an attacker comprmises a service principal via a compromised owner or compromised secret/cert+key, the will be acting in the context of that service principal when leveraging API access. That can be incredibly hard to see depending on the skill of the adversary. You really need to understand that there's no good way to secure Client Secrets or Certificate+Key. If you have 2 owners for every app registration, those owners can do the following things: 1. Add Secrets, Certificates+Keys, Federations 2. Change Manifests 3. Add/change redirect URIs 4. Change the audience to a multi-tenant app 5. Add dynamic or incremental delegated permissions at runtime that don't require admin consent 6. Provisioning 7. Add assignment 8. Harvest consents for lateral movement 9. Add additional owners 10. Move laterally to other tenants via consent phishing Often times, the application will have more permissions granted through the APIs than the application owner. This is a privilege escalation. Unfortunately, at this time, Microsoft recommends having 2 application owners for governance reasons. This recommendation does not account for the added attack surface. Adding app registration owners is giving someone the equivqalent of Application Administrator for that single application, at a minimum, and often more. If you can, use the serviceManagementReference tag to document application ownership for app registrations instead. When users leave, create an automation that checks thopse serviceManagementReference tags and update as necessary. Yes, we need to govern. We also need security. Only your the following roles should be managing anything related to your Entra App Registrations: Cloud Application Admin, Application Admin, Privileged Role Admin, Global Admin. youtube.com/watch?v=8kAO9T…
YouTube video
YouTube
English
2
6
51
6.3K
Sonny
Sonny@SonBoyJim·
@IAMERICAbooted @NathanMcNulty @fabian_bader @merill Thanks Erica. That’s right. Also just standard service principals can fly under the radar. Eg. Microsoft PIN Reset Service for WHfB pin resets, shows as external app, not verified, might not be used for a while but if I removed then it would break that service.
English
2
0
2
32
EZ
EZ@IAMERICAbooted·
@NathanMcNulty @fabian_bader @SonBoyJim @merill Maybe those apps dont exist anymore. Maybe those addins are no longer in use. Maybe its a back door for persistence. The problem is not knowing what they are ans whether they should be disabled
English
1
0
1
49
Sonny
Sonny@SonBoyJim·
@IAMERICAbooted @merill Great chat as always! I’m currently removing unused service principals from our tenant using ENow App Gov. Do you know if there is a documented list of apps that should remain that MS services rely on that should be left. A few sus apps appearing in my stale report 😂
English
1
0
1
50
Merill Fernando
Merill Fernando@merill·
Now that I'm no longer at Microsoft, I'm free to share some of my rebel tips 😎 Who wants me to post them?
English
91
16
618
148.5K
XBOX UK
XBOX UK@xboxuk·
START THOSE ENGINES, JAPAN AWAITS 🌸🏎️ To celebrate the upcoming release of Forza Horizon 6, we're giving away 6 Premium Edition digital codes of the game. For your chance to win, follow @XboxUK AND: 💚 Comment for an Xbox Code 🔁 Repost for a Steam Code Winners will be chosen on Friday the 15th of May
XBOX UK tweet media
English
5.6K
9.3K
14K
949.1K
Sonny retweetledi
Jynxzi
Jynxzi@jynxzi·
1st place in $100k Chess Tournament 🥇 Giving away $20,000 to 10 people who like & RT ❤️
English
21.3K
65K
108.5K
4.8M
Choppy
Choppy@ChoppyTech·
@IAMERICAbooted Any SASE providers you would recommend or more importantly avoid?
English
2
0
1
77
EZ
EZ@IAMERICAbooted·
If your SASE provider doesnt provide dedicated IP blocks for egress, get a new SASE provider
English
4
0
23
2.6K
Sonny
Sonny@SonBoyJim·
@EpicNewsroom Nice of you to mention other Epic games like Rocket League in this post… Can clearly see where your priorities lie. Can you give the game back to Psyonix please 🙏
English
0
0
0
18
Sonny
Sonny@SonBoyJim·
@NathanMcNulty @PyroTek3 Yep! The best thing is you share so much and when relevant to us we will always review whatever that is and implement when we can 😊 it was relieving to know that we had most of the recommended protections for the Wiper attack, big thanks for that! 🙏
English
0
0
1
8
Sonny
Sonny@SonBoyJim·
@IAMERICAbooted Thanks Erica. We are doing most of this. We require complaint devices for our priv admins but can you help me with the detail on the point on device trust being appropriately configured? Quite sure our CAP just states device must be compliant.
English
1
0
1
210
EZ
EZ@IAMERICAbooted·
Nathan is talking about GA. Let's talk about Intune Admin because thats all that is required for the Stryker incident. If your GA gets popped, sorry, idk what to tell you. Everyone knows how dangerous it is. We've been saying it for years, especially me with Intune Admins. BEST CHOICE IS ALWAYS PAWS!! OTHER OPTIONS? Admin must not be able to login to Intune portal unless: ***a. FIDO2 Authn ***b. MANAGED device required in CAP with device filters where device trust is appropriately configured ***c. Must come from specific IP of SWG aka Named Locations/Zones d. PIM requires another admin approval. e. Validate EDR is checking at all times f. Restricted browsers - NO EMAIL Allowed!! NO TEAMS!! NO CHAT APPS!! Just admin stuff!! g. Restricted admin units h. Intune Specific RBAC to decrease blast radius This is not a pick one or two list. A, B, and C must be all included. This day in age knowing the current threat landscape, your admin devices should have Restricted browsing and no email. The threat landscape has evolved a lot in the past year and phishing has gotten incredibly hard to spot when you are facing a very advanced mean nerd.
Nathan McNulty@NathanMcNulty

If you think Intune's multi-admin mode is going to save you from a phished Global Admin, I have bad news... GA can just create a second admin and approve their change ;)

English
10
12
94
20.2K
Sonny
Sonny@SonBoyJim·
@IAMERICAbooted @NathanMcNulty @acjuelich Thanks for all your insight! We don’t use Okta just Entra as the IdP but as we are trying to achieve compliance with regular and admin accounts on the same Entra ID Joined device I guess that is where the conflict is. To get device info we had to sign in at device level for both
English
1
0
1
21
EZ
EZ@IAMERICAbooted·
For example, if you have okta, its a separate addon that a lot orgs dont have. Then they are not able to receive device properly in the federated idp. Prisma has a way you can do that too, but then IT acts as the primary idp and sends the authn back to the other idp to finish the flow with entra. Its a mess. Lots of ways to do this but federations make it challenging
English
1
0
0
23
Adam Juelich
Adam Juelich@acjuelich·
Once you start leveraging device-based Conditional Access Policies, Incognito/InPrivate mode becomes problematic. Any strategies around that, or am I overthinking it? I use those modes a lot. @NathanMcNulty @IAMERICAbooted
English
6
2
23
5K
Sonny
Sonny@SonBoyJim·
@IAMERICAbooted @NathanMcNulty @acjuelich Thanks & Sorry Erica! It is actually the PA Prisma VPN. It doesn’t use CIE just direct Entra SAML auth. Both standard and admin accounts are signed in at OS level on our devices. Even when I open admin portals with my admin profile I get prompted on which account to use 😵‍💫
English
2
0
1
15
Sonny
Sonny@SonBoyJim·
@NathanMcNulty @acjuelich @IAMERICAbooted Hi Nathan, we don’t have separate device for admin access but we do use profiles as we require device compliance for both accounts. The issue we have is we have to ‘select an account to use’ when our always on VPN authenticates using Entra as the IdP. Sometimes admins miss 1/2
English
2
0
1
21