The #TROOPERS26 ‘AD & Entra ID Security’ track delivered an incredible experience – much like the entire conference! We were thrilled to host some of the brightest minds in identity research alongside a highly engaged audience who brought valuable insights to the roundtable discussions. While the presentation slides have already been published on the TROOPERS website, several speakers have shared complementary tools, in-depth blog posts, and active social media threads. To make things easy, we’ve compiled a comprehensive list of all these fantastic resources from the track below.
We can’t wait to see you all again next year at #TROOPERS27!
Alexander Neff & Phil Knüfer – ESC17: Using ADCS to Attack HTTPS-Enabled WSUS Clients
Alexander and Phil demonstrated how combining ADCS certificate template vulnerabilities with WSUS Man-in-the-Middle techniques can compromise HTTPS-enabled WSUS clients. By abusing specific certificate configurations, they showed that even patched and best-practice Windows environments can fall victim to remote code execution. They categorized this generalized certificate template misconfiguration under the new designation “ESC17.”
- Abstract: here
- Slides: here
- Video: here
- Tooling: wsuks
- Blogpost: Using ADCS to Attack HTTPS-Enabled WSUS Clients
- Socials: Alexander Neff (@al3x_n3ff (X), @al3x-n3ff.bsky.social, LinkedIn), Phil Knüfer (@cookieTheft (X), @cookietheft@ioc.exchange (Mastodon), LinkedIn)
Thomas Naunheim & Martin Sohn Christensen – Tier Breakers: Blind Spots in Cloud-Managed PAWs
Thomas and Martin highlighted security blind spots in cloud-managed Privileged Access Workstations (PAWs) governed by Intune and Entra ID. They demonstrated how implicit permissions, Intune RBAC scope misconfigurations, and platform constraints allow attackers to break administrative tier boundaries within single and multi-tenant environments. To help organizations measure their exposure, they introduced enumeration methods and tooling to identify tier boundary violations.
- Abstract: here
- Slides: here
- Video: here
- Tooling: BloodHound OpenGraph, EntraOps
- Socials: Thomas Naunheim (@Thomas_Live (X), LinkedIn Naunheim.cloud (Bluesky), GitHub), Martin Sohn Christensen (@martinsohndk (X), LinkedIn, Martinsohn.dk (Bluesky) GitHub)
Shang-De Jiang & Jun Sheng Shi – Nested APP Authentication – Undocumented Risk and Conditional Access Bypass
Shang-De and Jun Sheng investigated the security risks of Nested APP Authentication (NAA), a broker-client token exchange protocol used by Microsoft apps like Teams and Outlook. They demonstrated how NAA’s silent pre-authorization allows attackers to exploit misconfigurations in Conditional Access include/exclude rules to bypass MFA, device compliance, and token protection. Their findings emphasize that Conditional Access policy design must carefully evaluate app inclusion and exclusion rules to prevent unauthorized cross-resource access.
- Abstract: here
- Slides: Coming soon
- Video: Coming soon
- Socials: Jun Sheng Shi (LinkedIn), Shang-De ‘John’ Jiang (@SecurityThunder (X))
Dr Nestori Syynimaa – Trusted by Design: How Windows Uses TPM to Secure PRTs
Nestori analyzed how Windows leverages Trusted Platform Modules (TPM) to safeguard Primary Refresh Tokens (PRTs) and Session Keys during Entra ID device joins. He detailed the cryptographic key pair exchange between Windows devices and Entra ID, while examining potential attack vectors targeting TPM-backed credentials. His findings shed light on the effectiveness -and limitations- of hardware-rooted protection against credential theft.
- Abstract: here
- Slides: here
- Video: here
- Socials: @DrAzureAD (X)
Sapir Federovsky & Shahar Dorfman – Do Apps Have Imposter Syndrome? Unmasking Token Theft Campaigns
Sapir and Shahar uncovered widespread malicious OAuth application campaigns that exploit the relationships between Application Registrations and Service Principals across dozens of organizations. They explained why standard security controls fail to spot consent flow abuses and presented a detection model called “Next Campaign Finder.” This approach correlates metadata across tenants to score and detect high-risk or imposter applications.
- Abstract: here
- Slides: here
- Video: here
- Blogpost: Automatically detecting malicious Azure OAuth applications using LLMs
- Socials: @sapirxfed (X), @shahardorf (X)
Geoffrey Sauvageot-Berland – Windows Deployment Service: An AD Blind Spot?
Geoffrey explored security vulnerabilities in Windows Deployment Services (WDS) and the Microsoft Deployment Toolkit (MDT), which frequently linger unmonitored in Active Directory networks. He illustrated how legacy PXE boot configurations and default administrative setups enable supply chain attacks and unauthorized internal access. To assist defenders and auditors, he also released a NetExec module targeting these deployment weaknesses.
- Abstract: here
- Slides: here
- Video: here
- Tooling: NetExec PR #1194
- Socials: LinkedIn
Raz Tel-Vered – From Packets to Intent: Hunting Adversaries in AI Telemetry
Raz outlined a threat hunting framework for AI telemetry, shifting focus from traditional packet or process signatures to analyzing natural language intent. He demonstrated how converting prompts, responses, tool calls, and RAG retrievals into semantic embeddings enables defenders to detect prompt injection, capability probing, and privilege escalation across multiple languages.
Dirk-jan Mollema – I’m_in_your_cloud_v4_FINAL.pdf – hacking everyone’s cloud
Dirk-jan shared a retrospective of his multi-year journey researching hybrid Active Directory and Entra ID security since his first TROOPERS talk in 2019. He traced the evolution of cloud identity tooling and architectural research that ultimately led to the discovery of Actor Token vulnerabilities and a CVSS 10.0 flaw in Microsoft’s core identity infrastructure.
- Abstract: here
- Slides: here
- Video: here
- Tooling: ROADtools
- Blogpost: Exploiting Actor Tokens in Entra ID (CVE-2025-55241)
- Socials: @_dirkjan (X), @dirkjanm.io (Bluesky)
Michael Grafnetter – KDS Root Keys: All Secrets Finally Revealed
Michael demystified Key Distribution Service (KDS) Root Keys in Active Directory, unpacking how these master seeds drive gMSA, dMSA, and DPAPI-NG protections. He introduced novel online and offline attack techniques capable of decrypting sensitive data, including BitLocker volumes protected by SID Protectors.
- Abstract: here
- Slides: here
- Video: here
- Blogpost: Directory Services Internals Blog, Juicing ntds.dit Files to the Last Drop
- Socials: @MGrafnetter (X)
Simon Maxwell-Stewart – Popping Microsoft’s Sandbox: What Falls Out of a Dataverse Container
Simon recounted how registering a custom .NET plugin in Microsoft Dataverse led to full SYSTEM compromise of isolated Windows Server containers. By extracting internal DLLs and credentials from the container environment, his team reverse-engineered Microsoft’s unauthenticated internal gRPC sandbox protocols.
- Abstract: here
- Slides: here
- Video: here
- Blogpost: Popping Microsoft’s Sandbox: Dataverse Security Risks in Plugin Containers
- Socials: @KIDTRONNIX (X), @btphantomlabs (X)
Karl Fosaaen & Thomas Elling – Modern Adventures in Azure Privilege Escalation
Karl and Thomas provided a practical guide to modern privilege escalation in Azure and Entra ID environments. They walked through techniques for converting initial footholds and read-only access into full administrative control, abusing service permissions, and pivoting back into on-premises domain networks.
- Abstract: here
- Slides: here
- Video: here
- Tooling: AzurePentestingWiki, AzurePentestingWiki GitHub, MicroBurst
- Socials: Karl Fosaaen (@kfosaaen (X)), Thomas Elling (LinkedIn)
Martin Haller – RansomCloud: Ransomware Operations in Microsoft 365
Martin examined how ransomware operators are increasingly shifting focus from on-premises networks to Microsoft 365 environments. He analyzed attacker tactics that exploit the lack of cloud-native monitoring in conventional endpoint and perimeter security solutions, demonstrating how attackers execute extortion directly within cloud tenants.
Stav Setty – Jingle Thief: Cloud Identity Tradecraft in Microsoft 365 and Entra ID
Stav analyzed “Jingle Thief,” a financially motivated threat campaign operating almost entirely inside Microsoft 365 and Entra ID. She mapped out how the threat actors leveraged phishing for initial access, manipulated mailbox rules for internal expansion, and altered Entra ID authentication settings to maintain long-term stealthy persistence.
- Abstract: here
- Slides: here
- Video: here
- Blogpost: Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign
- Socials: Stav Setty (LinkedIn)
Upcoming trainings from ERNW instructors
- Entra ID Security Essentials training in August, September and November.
- Hardening Microsoft Environments training in October and December.
Recent research contributions from ERNW experts