Thijs Lecomte

2.2K posts

Thijs Lecomte banner
Thijs Lecomte

Thijs Lecomte

@thijslecomte

Microsoft MVP, #MEM, #Security and #Automation. Technical Editor for https://t.co/XtSjS7BiZr. Security @ https://t.co/paena7PabW. Tweets are my own

Belgium Katılım Ocak 2010
280 Takip Edilen1.8K Takipçiler
Ru Campbell
Ru Campbell@rucam365·
@thijslecomte Ah, understood - I thought you mean a GDAP read-type permission had similar implications. Another example of why I don't trust this role when doing security assessments.
English
1
0
0
127
Ru Campbell
Ru Campbell@rucam365·
Reminder: Entra ID global reader is “global” in same way I was “world” champion wrestling as a child on a trampoline. Hard to fully trust this role with anything important like security audits.
Brian Reid (Microsoft 365 MVP)@BrianReidC7

The recent licence management by groups change in #EntraID (i.e. use M365 Admin Center) needs to go back to the drawing board - group assignment is not visible to Global Reader role when it used to be. Any comments @merill ? @azuread ?

English
4
0
17
3.2K
Thijs Lecomte
Thijs Lecomte@thijslecomte·
@rucam365 As an admin, you cannot view GDAP delegations with global reaser
English
1
0
1
51
Ru Campbell
Ru Campbell@rucam365·
@thijslecomte Does it have the same limitations as Global Reader? I do not do much with MSP/multi-tenant to know.
English
1
0
1
68
Thijs Lecomte
Thijs Lecomte@thijslecomte·
@rucam365 I have two 27" 4K myself. It's easier for me to share screens and keep an overview. As an IT guy working from home, I share my screen multiple times a day
English
0
0
3
270
Ru Campbell
Ru Campbell@rucam365·
Thinking of upgrading the home office monitors and wonder what setup folks use and recommend? Currently 3x 1920x1080 24" monitors side by side. Which would you go for: 3x 4K monitors, an ultrawide, or some kind of combo? Mostly running VM labs, Office and web, scripting, etc.
English
52
2
20
13.9K
Thijs Lecomte
Thijs Lecomte@thijslecomte·
Just released a new blog talking about a new CA feature which I have been waiting on for a long time. This allows us to better protect our administrator users against token theft and opens up new ways to secure critical applications. 365bythijs.be/2024/02/27/a-n… #entraid #ca
English
0
1
15
1.6K
Thijs Lecomte
Thijs Lecomte@thijslecomte·
This weekend, I deep dived into the Microsoft hack to see how it happened and what we learned from it. I linked it to the @ENowConsulting 's Application Governance, which provides insightful recommendations into some common misconfigurations appgovscore.com/blog/insecure-…
English
0
2
4
300
Thijs Lecomte
Thijs Lecomte@thijslecomte·
@rucam365 What's the source on this Ru? Haven't seen this article myself
English
1
0
0
318
Ru Campbell
Ru Campbell@rucam365·
I'm slow, the wording isn't crystal, or both. What happened, specifically? • APT29 is able to create a user in Microsoft's production tenant -> gets assigned privileged role -> can self-approve OAuth app or • Tricked production tenant admin into approving the OAuth app ?
Ru Campbell tweet media
English
11
7
24
7.3K
Thijs Lecomte
Thijs Lecomte@thijslecomte·
Apps within Entra ID remain a security risk in a lot of companies... Check out the blog below on how you can protect your organization against it!
ENow Software@ENowConsulting

💥App Registrations are highly privileged & often used by #threatactors for privilege escalation attacks in #EntraID 👉 Microsoft MVP @thijslecomte explains how you can protect your organization with the proper permissions in place for attack prevention: enow.software/48vZi4u

English
0
0
5
876
Thijs Lecomte
Thijs Lecomte@thijslecomte·
If you like in-depth articles, check out this one below! It covers, in great detail, how an attack in a cloud environment looks like and how to detect it. Including initial access, persistence, reconnaissance and privilege escalation.
Robbe Van den Daele@RobbeVdDaele

I wrote a blog post about how Entra ID Joined and Hybrid Joined devices can be used to move to #entraid and #cloudsolutions, how to detect it, and what preventive controls you can use. 📜hybridbrothers.com/device-to-entr… #microsoftsecurity #hybridbrothers

English
0
3
10
1.7K