SlideShare a Scribd company logo
ACCESS POLICIES
FINDING HOLES
IN CONDITIONAL
Cloud Village - DC32
WHOAMI
BRANDON COLLEY
@TECHBRANDON
FOUNDER - BNR CONSULTING
SERVICE LEAD & SENIOR
SECURITY CONSULTANT -
TRIMARC
Common misconfigurations Why they matter What you can do about it
LARGE NUMBER OF
POLICIES
17 REPLIES
High/Low: 16 - 120
Average: 57.7
LARGE NUMBER OF
POLICIES
LARGE NUMBER OF
POLICIES
REQUIRE MFA FOR
ADMINS
14 ROLES BY DEFAULT
Global Administrator
Security Administrator
SharePoint Administrator
Exchange Administrator
Conditional Access Administrator
Helpdesk Administrator
Billing Administrator
User Administrator
Authentication Administrator
Application Administrator
Cloud Application Administrator
Password Administrator
Privileged Authentication Administrator
Privileged Role Administrator
REQUIRE MFA FOR
ADMINS
14 ROLES BY DEFAULT
Global Administrator
Security Administrator
SharePoint Administrator
Exchange Administrator
Conditional Access Administrator
Helpdesk Administrator
Billing Administrator
User Administrator
Authentication Administrator
Application Administrator
Cloud Application Administrator
Password Administrator
Privileged Authentication Administrator
Privileged Role Administrator
ADD AT LEAST:
Authentication Policy Administrator
Directory Writers
External Identity Provider Administrator
Hybrid Identity Administrator
Identity Governance Administrator
Intune Administrator
License Administrator
Partner Tier 1 Support
Partner Tier 2 Support
REQUIRE MFA FOR
ADMINS
NAMED LOCATIONS
SUBNETS!!!
Regular maintenance
Narrow scopes
Overlapping IP space
MULTIPLE
CONDITIONS
MULTIPLE
CONDITIONS
FINDING
HOLES
FINDING
HOLES
FINDING
HOLES
FINDING
HOLES
FINDING
HOLES
FINDING
HOLES
BUILT IN TOOLS
IDPOWERTOYS
IDPOWERTOYS
IDPOWERTOYS
MAESTER.DEV
MAESTER.DEV
MAESTER.DEV
s
INVOKE-CAPREVIEW
HTTPS://GITHUB.COM/TECHBRANDON/CAPS
INVOKE-CAPREVIEW
INVOKE-CAPREVIEW
@TECHBRANDON
LINKEDIN.COM/IN/TECHBRANDON
THANK YOU!
RESOURCES
https://entra.microsoft.com/#view/Microsoft_AAD_Conditio
nalAccess/ConditionalAccessBlade/~/Overview
https://learn.microsoft.com/en-
us/entra/identity/conditional-access/what-if-tool
https://idpowertoys.merill.net/ca
https://maester.dev/
https://github.com/techBrandon/CAPs
https://learn.microsoft.com/en-
us/entra/identity/conditional-access/howto-conditional-
access-policy-admin-mfa
https://techcommunity.microsoft.com/t5/microsoft-entra-
blog/introducing-the-microsoft-entra-powershell-
module/ba-p/4173546
@TECHBRANDON
LINKEDIN.COM/IN/TECHBRANDON
WRITE
YOUR
TOPIC
OR IDEA
ADD A MAIN POINT
Briefly elaborate on what you want to discuss.
ADD A MAIN POINT
Briefly elaborate on what you want to discuss.
ADD A MAIN POINT
Briefly elaborate on what you want to discuss.
Back to Agenda Page
Back to Agenda Page
WRITE YOUR
TOPIC OR IDEA
Briefly elaborate on what
you want to discuss.
Write a column name Write a column name Write a column name Write a column name Write a column name
WRITE YOUR TOPIC OR IDEA
Back to Agenda Page
Item 1
20%
Item 2
20%
Item 3
20%
Item 4
20%
Item 5
20%
WRITE
YOUR TOPIC
OR IDEA
Briefly elaborate on what
you want to discuss.
Back to Agenda Page
WHITEBOARD
PAGE
Write a note here
Write a
note here
Copy a note, drag
to the board, and
write your ideas.
Copy a note,
drag to the
board, and write
your ideas.
Tip: Collaboration makes teamwork
easier! Click "Share" and invite your
teammates to fill this up. Use this page
for bulletins, brainstorms, and other fun
team ideas.
Right-click on the background of the
slide, or on the thumbnail below, for the
option to expand this page into a
whiteboard for more space.
Brainstorm better! Set a
time limit for yourself
for a more focused
brainstorming session.
Tip: Collaboration makes teamwork
easier! Click "Share" and invite your
teammates to fill this up. Use this page
for bulletins, brainstorms, and other fun
team ideas.
Right-click on the background of the
slide, or on the thumbnail below, for the
option to expand this page into a
whiteboard for more space.
Add a main topic
Add a related idea
Add a related idea
Add a related idea
Add a related idea
Add more
sub-ideas
Add more
sub-ideas
Add even more
sub-ideas
Add even more
sub-ideas
Add more
sub-ideas
Add more
sub-ideas
Add even more
sub-ideas
Add even more
sub-ideas
RESOURCE
PAGE
Use these design resources in your
Canva Presentation. Happy designing!
Don't forget to delete or hide this
page before presenting.
RESOURCE
PAGE
Use these design resources in your
Canva Presentation. Happy designing!
Don't forget to delete or hide this
page before presenting.
B for blur C for confetti
D for a drumroll M for mic drop
O for bubbles Q for quiet
U for unveil
Any number from
0-9 for a timer
RESOURCE
PAGE
Find the magic and fun in presenting with
Canva Presentations. Press the following
keys while on Present mode!
Delete or hide this page before presenting.

More Related Content

Similar to Finding Holes in Conditional Access Policies (20)

PPTX
WordPress 101 - Foundation Friday at WordCamp Chicago 2014 #WCChi
Shanta Nathwani
 
PPT
Meet Process Design
Alan Crean
 
PPTX
Copy of Orange Red and Light Gray Cute Pastel 3D Shapes Company Business Prof...
Felix Jones Banares
 
PDF
Landing pages
WSI Egypt
 
PDF
Sap bo-universe-design-beginner-s-guide-part-i
Amit Sharma
 
PPTX
Open Web Technologies and You - Durham College Student Integration Presentation
darryl_lehmann
 
PDF
San Diego HubSpot User Group - Landing Pages Workshop
SD Inbound Marketing
 
PPT
Growing Your Business With A Website: WIBO
Mardy Sitzer
 
PPTX
Black Neon Green Neon Pink Trendy Illustrative Creative Presentation.pptx
EckoSunga
 
PPTX
Copie de Pink Blue and Yellow Purple Cute 3D Social Media Marketing Presentat...
instagramUP
 
PDF
Genial.ly - gamify and increase task productivity
TechnicalSupport25
 
PPTX
Tackling Teams & SharePoint Site Sprawl: Why It Matters & What You Need To Know
Richard Harbridge
 
KEY
"Twitter, Pray, Love" at State Policy Network 2010
Cord Blomquist
 
PPTX
How to Build an Accessible WordPress Theme
Graham Armfield
 
PPT
Ngo & social media drupal a match made in haven
Gdzine Net
 
PPTX
Advanced LinkedIn for the Power User (April 2016 Edition)
Pam Ann Marketing
 
PPTX
Black Purple Trendy Acid Brutalist Creative Presentation.pptx
pophope684
 
PPTX
PENDRAGON research base designing process
elblogzamperoo
 
PDF
presentation news
Lynx56
 
PPTX
Social Studies Subject for High School_ Immigration and Urbanization.pptx
HenriSandoval
 
WordPress 101 - Foundation Friday at WordCamp Chicago 2014 #WCChi
Shanta Nathwani
 
Meet Process Design
Alan Crean
 
Copy of Orange Red and Light Gray Cute Pastel 3D Shapes Company Business Prof...
Felix Jones Banares
 
Landing pages
WSI Egypt
 
Sap bo-universe-design-beginner-s-guide-part-i
Amit Sharma
 
Open Web Technologies and You - Durham College Student Integration Presentation
darryl_lehmann
 
San Diego HubSpot User Group - Landing Pages Workshop
SD Inbound Marketing
 
Growing Your Business With A Website: WIBO
Mardy Sitzer
 
Black Neon Green Neon Pink Trendy Illustrative Creative Presentation.pptx
EckoSunga
 
Copie de Pink Blue and Yellow Purple Cute 3D Social Media Marketing Presentat...
instagramUP
 
Genial.ly - gamify and increase task productivity
TechnicalSupport25
 
Tackling Teams & SharePoint Site Sprawl: Why It Matters & What You Need To Know
Richard Harbridge
 
"Twitter, Pray, Love" at State Policy Network 2010
Cord Blomquist
 
How to Build an Accessible WordPress Theme
Graham Armfield
 
Ngo & social media drupal a match made in haven
Gdzine Net
 
Advanced LinkedIn for the Power User (April 2016 Edition)
Pam Ann Marketing
 
Black Purple Trendy Acid Brutalist Creative Presentation.pptx
pophope684
 
PENDRAGON research base designing process
elblogzamperoo
 
presentation news
Lynx56
 
Social Studies Subject for High School_ Immigration and Urbanization.pptx
HenriSandoval
 

More from Cloud Village (18)

PPTX
Unexpected Leaks in AWS Transit Gateways
Cloud Village
 
PDF
The Rise of the Planet of the Agents: LLM-based AI Agents and Cloud Security ...
Cloud Village
 
PDF
Creating Azure Policy Compliant Backdoor
Cloud Village
 
PPTX
Kicking in the Door to the Cloud: Exploiting Cloud Provider Vulnerabilities f...
Cloud Village
 
PDF
Cloud Tripwires: fighting stealth with stealth
Cloud Village
 
PPTX
Connecting the Dots - Mastering Alert Correlation for Proactive Defense in th...
Cloud Village
 
PDF
Runtime Reachability: Prioritizing Vulnerabilities with eBPF & Continuous Pro...
Cloud Village
 
PPTX
Revealing Choke Points - Practical Tactics for Boosting Cloud Security
Cloud Village
 
PPTX
One Click, Six Services - Abusing The Dangerous Multi-service Orchestration P...
Cloud Village
 
PDF
Terraform Unleashed - Crafting Custom Provider Exploits for Ultimate Control
Cloud Village
 
PPTX
Workshop: Hands-On Container Image Security Mastering Sigstore for Unbreachab...
Cloud Village
 
PDF
DC 32: Epyon - Attacking DevOps environments
Cloud Village
 
PDF
Exploit K8S via Misconfiguration .YAML in CSP environments
Cloud Village
 
PDF
Cloud Offensive Breach and Risk Assessment (COBRA)
Cloud Village
 
PDF
One Port to Serve Them All - Google GCP Cloud Shell Abuse
Cloud Village
 
PDF
The Oracle Awakens: Demystifying Privilege Escalation in the cloud
Cloud Village
 
PDF
Catch them all! Detection engineering and purple teaming in the cloud
Cloud Village
 
PDF
Gone in 60 Seconds… How Azure AD/Entra ID Tenants are Compromise
Cloud Village
 
Unexpected Leaks in AWS Transit Gateways
Cloud Village
 
The Rise of the Planet of the Agents: LLM-based AI Agents and Cloud Security ...
Cloud Village
 
Creating Azure Policy Compliant Backdoor
Cloud Village
 
Kicking in the Door to the Cloud: Exploiting Cloud Provider Vulnerabilities f...
Cloud Village
 
Cloud Tripwires: fighting stealth with stealth
Cloud Village
 
Connecting the Dots - Mastering Alert Correlation for Proactive Defense in th...
Cloud Village
 
Runtime Reachability: Prioritizing Vulnerabilities with eBPF & Continuous Pro...
Cloud Village
 
Revealing Choke Points - Practical Tactics for Boosting Cloud Security
Cloud Village
 
One Click, Six Services - Abusing The Dangerous Multi-service Orchestration P...
Cloud Village
 
Terraform Unleashed - Crafting Custom Provider Exploits for Ultimate Control
Cloud Village
 
Workshop: Hands-On Container Image Security Mastering Sigstore for Unbreachab...
Cloud Village
 
DC 32: Epyon - Attacking DevOps environments
Cloud Village
 
Exploit K8S via Misconfiguration .YAML in CSP environments
Cloud Village
 
Cloud Offensive Breach and Risk Assessment (COBRA)
Cloud Village
 
One Port to Serve Them All - Google GCP Cloud Shell Abuse
Cloud Village
 
The Oracle Awakens: Demystifying Privilege Escalation in the cloud
Cloud Village
 
Catch them all! Detection engineering and purple teaming in the cloud
Cloud Village
 
Gone in 60 Seconds… How Azure AD/Entra ID Tenants are Compromise
Cloud Village
 
Ad

Recently uploaded (20)

PDF
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
PDF
Python basic programing language for automation
DanialHabibi2
 
PPTX
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
PDF
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
PDF
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
PDF
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
PPTX
MSP360 Backup Scheduling and Retention Best Practices.pptx
MSP360
 
PDF
"Beyond English: Navigating the Challenges of Building a Ukrainian-language R...
Fwdays
 
PDF
Blockchain Transactions Explained For Everyone
CIFDAQ
 
PPTX
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
PDF
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PDF
CIFDAQ Market Insights for July 7th 2025
CIFDAQ
 
PDF
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
PDF
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
PDF
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PDF
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
PDF
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
PDF
LLMs.txt: Easily Control How AI Crawls Your Site
Keploy
 
PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
Python basic programing language for automation
DanialHabibi2
 
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
MSP360 Backup Scheduling and Retention Best Practices.pptx
MSP360
 
"Beyond English: Navigating the Challenges of Building a Ukrainian-language R...
Fwdays
 
Blockchain Transactions Explained For Everyone
CIFDAQ
 
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
CIFDAQ Market Insights for July 7th 2025
CIFDAQ
 
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
LLMs.txt: Easily Control How AI Crawls Your Site
Keploy
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
Ad

Finding Holes in Conditional Access Policies