Advertisement · 728 × 90

Posts by Fabian Bader

Post image

My Disobey talk "Are passkeys as secure as you think" is now available on YouTube

youtu.be/DQ4dnXibaoM?...

1 month ago 9 0 0 0

Nothing new that I'm aware of

1 month ago 1 0 1 0

For your main identity you will use Windows hello for business. But if you have a secondary account this can be stored there

1 month ago 0 0 0 0
MC1247893 - Microsoft Entra passkeys on Windows now support phishing-resistant sign-in | Microsoft 365 Message Center Archive Microsoft Entra passkeys on Windows enable phishing-resistant, passwordless sign-in using Windows Hello on Entra-protected resources, including unmanaged devices. Public preview starts mid-March 2026....

Microsoft just announced official support to store device bound Passkeys for Entra ID in the Windows Hello container. No app, no external hardware key but built in support. Sadly no attestation while in preview.

mc.merill.net/message/MC12...

#Passkey #EntraID

1 month ago 9 3 2 0

What are preferred methods to lock someone out of a remote Intune managed computer? Any that work well in a hybrid configuration?

Our best solution to date is a push of a “deny local login” policy in advance and a forced reboot.

@nathanmcnulty.com @merill.net @fabian.bader.cloud

2 months ago 2 1 0 0

No it's live stream only

3 months ago 1 0 1 0
Preview
Yellowhat Yellowhat is a cutting-edge cybersecurity event dedicated to Microsoft Security Technology, offering advanced deep-dive sessions (level 400+) for seasoned professionals. It brings together experts and...

Today at 15:00 CET #YellowHat will start. It's a free live streamed conference around Microsoft Security and we have amazing speakers and topics lined up for you.

Register now to reserve your free spot.

yellowhat.live

#XDR #EDR #Defender #Microsoft #Security

3 months ago 3 1 1 0
Preview
Exclude analytics rules from correlation in Microsoft Defender XDR - Microsoft Defender XDR Learn how to exclude specific analytics rules from the correlation engine to maintain static incident grouping behavior similar to Microsoft Sentinel.

With the unified SOC experience there might be some ANRs you want to exclude from XDR correlation. Now you can!

Either using the UI or add #DONT_CORR# at the beginning of the ANR description.

learn.microsoft.com/en-us/defend...

3 months ago 1 0 0 0
Advertisement
Post image

#ConsentFix is a great way for attackers to work around some protective layers but not all. @naunheim.cloud , @cbrhh.bsky.social and I wrote a blog post on detection and mitigations. Hope you find it useful and can adapt it to your environment.

www.glueckkanja.com/de/posts/202...

3 months ago 8 3 0 0

Congratulations. This is great news

3 months ago 1 0 0 0
Post image

We’re thrilled to reveal our next MC2MC Connect speakers for February 5th in Antwerp: @fabian.bader.cloud @rogierdijkman.bsky.social ! 🎙️

➡️Looking to explore the program or secure your spot? Check out: connect.mc2mc.be

#MC2MC #ConnectMC2MC #ConnectMC2MC2026 #Connect #Collaborate #Create

4 months ago 4 1 0 0
TROOPERS25: Finding Entra ID CA Bypasses - The Structured Way
TROOPERS25: Finding Entra ID CA Bypasses - The Structured Way YouTube video by TROOPERS IT Security Conference

@_dirkjan and my joint talk at #TROOPERS25 is now available on YouTube.

"Finding Entra ID CA Bypasses - the structured way" @wearetroopers.bsky.social

youtu.be/yYQBeDFEkps

4 months ago 6 3 0 0
Post image

🚀 The speakers for MC2MC Connect 2026 are live!

➡️ Dive into Microsoft Cloud, Endpoint, Security, AI, FinOps & Architecture with top experts.

🎤 Speakers: connect.mc2mc.be/speakers-wid...

🎟️ Only a few early-bird tickets left: connect.mc2mc.be/tickets/

#MC2MC #ConnectMC2MC #ConnectMC2MC2026

4 months ago 5 3 0 0
Post image

Custom data collection in Microsoft Defender for Endpoint was just announced in the November release notes.

Documentation is already available

learn.microsoft.com/en-us/defend...

Predictive shielding sounds also very interesting...
#MDE #XDR

5 months ago 2 0 0 0

Attackers found a clever way to abuse legitimate, digitally signed software to load malware and it's working.

Expel Intel’s Marcus Hutchins (@malwaretech.com) breaks down a campaign that weaponizes Greenshot, a legit screenshot tool, to evade detection at multiple layers. 🧵

5 months ago 29 7 1 0
Post image

Microsoft Defender just got the September 2025 update

◽Improved core service startup behavior
◽ Security fixes for missing input validation of RPC services
◽Fixed threat exclusion handling
◽Restored performance optimization for network file access

learn.microsoft.com/en-us/defend...

5 months ago 5 0 0 0
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...

7 months ago 87 37 9 5
Preview
Workplace Ninja Summit 2025: What does Swiss cheese and Conditional A... View more about this event at Workplace Ninja Summit 2025

Did you ever asked yourself: What does Swiss cheese and Conditional Access have in common?

Either way, if you want to learn about (un)documented Conditional Access Bypasses, then join me on Monday at the Workplace Ninja Summit 25

#WPninjas
wpninjas25.sched.com/event/27VE4/...

7 months ago 2 0 0 0
Advertisement

Not entirely sure as well but I think it's the same reason as @nathanmcnulty.com wrote.

7 months ago 2 0 1 0
Preview
Microsoft Sentinel’s AI-driven UEBA ushers in the next era of behavioral analytics | Microsoft Community Hub Co-author - Ashwin Patil Security teams today face an overwhelming challenge: every data point is now a potential security signal and SOCs are drowning in...

Sentinel UEBA got a welcome set of new data sources

◽Defender XDR device logon events
◽Entra ID managed identity signin logs
◽Entra ID service principal signin logs
◽AWS CloudTrail
◽GCP audit logs
◽Okta MFA

techcommunity.microsoft.com/blog/microso...

7 months ago 2 0 0 0
Post image

Token Protection in Microsoft Entra Conditional Access for Windows is now GA! 🎉

#EntraID #Token

learn.microsoft.com/en-us/entra/...

7 months ago 6 1 0 1
Preview
Detect threats using GraphAPIAuditEvents - Part 3 For a long time now, defenders had the ability to monitor behavior of human- and workload identities in Entra tenants not only through AuditLogs but with high level of insight with the MicrosoftGraphA...

Two years ago I published a two part series on #MSGraph logs and how to use them for threat hunting.

Now comes part 3 and the logs are finally available to the masses.

#EntraID #KQL #Security

cloudbrothers.info/en/detect-th...

8 months ago 4 1 0 0
Post image

Recently, we announced the finalists for the most special of the #GoldenClippyAwards The #ChuckNorris award is for heroes in multiple areas: @nathanmcnulty.com @fabian.bader.cloud @bindertech.se @knudsenm.bsky.social@mortenknudsen.net Congratulate them/reshare for these rockstars! #MVPBuzz #WPNinjas

8 months ago 3 2 0 1
Post image

Defender AV Platform v4.18.25070.5

◽Enhanced Passive Mode Scanning Behavior
◽Improved Tamper Protection Handling
◽Digital Signature Verification Performance Boost
◽Refined ASR Rule Exclusion Processing

#MDAV #MDE #ASR

8 months ago 5 1 0 0
Preview
Microsoft Entra Conditional Access token protection explained - Microsoft Entra ID Learn how to secure your environment with token protection in Microsoft Entra Conditional Access policies.

A rare, but highly welcome change. Microsoft changed the license requirement for Token protection from Entra ID P2 to P1.

This will protect more customers in the long run and lead to a more secure ecosystem.

learn.microsoft.com/en-us/entra/...

8 months ago 10 4 0 0
Customer guidance for SharePoint vulnerability CVE-2025-53770 | MSRC Blog | Microsoft Security Response Center Customer guidance for SharePoint vulnerability CVE-2025-53770

🚨 PSA - Zero day in SharePoint on-prem is actively exploited!

◽ Have Defender AV active
◽ Don't disable AMSI integration of SharePoint
◽ Keep an eye out for the alerts outlined in the article
◽ Look for post exploitation with the hunting query

msrc.microsoft.com/blog/2025/07...

8 months ago 6 1 0 0
Advertisement
Overview of NTLM auditing enhancements in Windows 11, version 24H2 and Windows Server 2025 - Microsoft Support Summary of new auditing features and deployment details

Part 8053 of eleventy billion on our path to killing NTLM: way way way way way better auditing.

support.microsoft.com/en-us/topic/...

9 months ago 46 12 3 0
Post image

What r u doing while cooking?
That’s my distraction ….
#PSConfEU 2915

9 months ago 4 2 0 0
Preview
Azure AD Graph retirement Migrate your applications using Azure AD Graph APIs scripts to Microsoft Graph before September 2025.

The latest on the Azure AD Graph retirement mentions two temporary outage tests and more guidance.

If something stops working it might be because of those tests.

#Entra #AADGraph

techcommunity.microsoft.com/blog/microso...

9 months ago 0 0 0 0
Post image

One of the results of the joined research with @dirkjanm.io is entrascopes.com

Basically the yellow pages for Microsoft first party apps.

#TROOPERS25

9 months ago 25 6 2 0