Bypassing Entra ID Conditional Access Like APT: A Deep Dive Into Device Authentication Mechanisms

  Рет қаралды 3,620

Black Hat

Black Hat

Күн бұрын

Bypassing Entra ID Conditional Access Like APT: A Deep Dive Into Device Authentication Mechanisms for Building Your Own PRT Cookie
Entra ID Conditional Access is a security feature that apply the right access controls for securing Microsoft cloud infrastructure. Conditional Access takes signals from various sources into account when making access decisions. One of the major signals is Deivce; Conditional Access can require device marked as compliant or Microsoft Entra hybrid joined device for authentication. In this talk, we will dive into the internal workings of identifying device when authenticating to Entra ID. The device certificate and session key are key components of device identification, and they are mostly protected by TPM (Trusted Platform Module). During the research into the protocols, we have discovered how attackers can interact with the device certificate and key, and eventually bypass device authentication of Conditional Access without even needing Administrator privileges on the device. There are several patches against abusing the device identities. However, we have implemented this attack through reverse-engineering Microsoft authentication library and there is no-fix, as we have reported this to Microsoft. In this talk, we will walk your through all the details of the device authentication flow and attacks into the mechanisms for bypassing Conditional Access. Also, we will give some insights into how to defend and detect this attack.
By:
Yuya Chudo | Senior Advisor, Secureworks Japan K. K.
Takayuki Hatakeyama | Senior Advisor, Secureworks Japan K. K.
Full Abstract & Presentation Materials:
www.blackhat.c...

Пікірлер
API Authentication: JWT, OAuth2, and More
6:12
ByteMonk
Рет қаралды 25 М.
Quando A Diferença De Altura É Muito Grande 😲😂
00:12
Mari Maria
Рет қаралды 45 МЛН
Enceinte et en Bazard: Les Chroniques du Nettoyage ! 🚽✨
00:21
Two More French
Рет қаралды 42 МЛН
Kerberos Authentication Explained | A deep dive
16:52
Destination Certification
Рет қаралды 369 М.
Learn Conditional Access in just 25 Mins
25:47
Andy Malone MVP
Рет қаралды 38 М.
Exploring OAuth 2.0: Must-Know Flows Explained
12:22
Code and Stuff
Рет қаралды 1,8 М.
Three New Attacks Against JSON Web Tokens
40:18
Black Hat
Рет қаралды 7 М.
Breaking Managed Identity Barriers In Azure Services
43:57
Black Hat
Рет қаралды 1 М.
Microsoft Entra external ID overview
9:27
Microsoft Security
Рет қаралды 1,5 М.
Block Personal Computers with Conditional Access in Microsoft 365
9:19
Jonathan Edwards
Рет қаралды 21 М.
How to Find MFA Bypasses in Conditional Access Policies
12:46
Beau Bullock
Рет қаралды 35 М.