Entra.Chat

Entra & Azure Power-Up: Secure Service Principal Impersonation with Simon Gottschlag


Listen Later

In this episode, Simon Gottschlag, CTO of Co-native and a Microsoft MVP in Azure, discusses his innovative prototype for implementing Azure service principal impersonation using Azure Functions and Key Vault.

We explore the challenges of managing service principals, the journey to building a solution, and the potential for improving developer experience in platform building. Simon shares insights on the four-eyes principle, Entra ID's newer attribute-based access control (ABAC) vs the traditional RBAC model, and how his solution can enhance security and auditability in Azure environments.

LinkedIn - https://www.linkedin.com/in/simongottschlag

πŸ”— Related Links

* Azure Service Principal Impersonation - https://github.com/co-native-ab/azure-service-principal-impersonation

* pimctl - https://github.com/co-native-ab/pimctl

πŸ“— Chapters

00:00 Intro

00:42 Meet Simon: CTO & Azure MVP

01:51 The Project: Azure Service Principal Impersonation

02:11 The Problem: Challenges in Managing Service Principals

03:47 Journey to the Solution: Building Platforms & Terraform Pain Points

06:50 The Challenge with Graph Permissions & Least Privilege

08:27 Improving Developer Experience in Platform Building

11:05 The Core Issue: Running Operations Locally vs. Service Principals

13:43 The Idea: Service Principal Impersonation

13:50 Four-Eyes Principle and PIM in Azure

15:40 Understanding Attribute-Based Access Control (ABAC)

18:58 Enforcing Role Delegation with ABAC and PIM

20:12 Clarifying Service Principal Access with PIM and Four-Eyes

21:26 The Local Development Dilemma with Security Principles

22:02 PIM CTL: A CLI Tool for PIM

22:42 New Challenge: Azure Managed Grafana & Terraform Authentication

23:36 AC Identity Terraform Provider: Getting Tokens from Entra

24:42 The Big Question: Securely Getting Service Principal Tokens Locally

25:21 What is Impersonation in This Context?

26:27 Building the Solution: Federated Credentials & Custom Token Exchange

28:42 How the Azure Function Works: Authentication & Token Issuance

29:26 The Result: Consistent Workflow & Auditability

31:05 Open Source: How to Set Up and Try the Prototype

33:31 Use Cases: DevOps Automation & Time-Limited Access

35:15 Potential: Multi-Cloud Deployments & Extending Entra

Podcast Apps

🎧 Apple Podcast β†’ https://entra.chat/apple

πŸ“Ί YouTube β†’ https://entra.chat/youtube

πŸ“Ί Spotify β†’ https://entra.chat/spotify

🎧 Overcast β†’ https://entra.chat/overcast

🎧 Pocketcast β†’ https://entra.chat/pocketcast

🎧 Others β†’ https://entra.chat/rss

Merill's socials

πŸ“Ί YouTube β†’ youtube.com/@merillx

πŸ‘” LinkedIn β†’ linkedin.com/in/merill

🐀 Twitter β†’ twitter.com/merill

πŸ•Ί TikTok β†’ tiktok.com/@merillf

πŸ¦‹ Bluesky β†’ bsky.app/profile/merill.net

🐘 Mastodon β†’ infosec.exchange/@merill

🧡 Threads β†’ threads.net/@merillf

πŸ€– GitHub β†’ github.com/merill



Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
...more
View all episodesView all episodes
Download on the App Store

Entra.ChatBy Merill Fernando

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like Entra.Chat

View all
Risky Business by Patrick Gray

Risky Business

361 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

626 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

366 Listeners

Hacked by Hacked

Hacked

176 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,006 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

312 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,879 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

The Practical 365 Podcast by Practical 365

The Practical 365 Podcast

9 Listeners

The Azure Security Podcast by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

The Azure Security Podcast

24 Listeners

Big Technology Podcast by Alex Kantrowitz

Big Technology Podcast

441 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

127 Listeners

Blue Security by Andy Jaw & Adam Brewer

Blue Security

14 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

43 Listeners